Page MenuHomePhabricator

Add a granular capability for user directory browsing
ClosedPublic

Authored by epriestley on Jan 30 2014, 7:40 PM.
Tags
None
Referenced Files
Unknown Object (File)
Mon, Apr 15, 4:59 AM
Unknown Object (File)
Sat, Apr 13, 7:37 PM
Unknown Object (File)
Thu, Apr 11, 10:31 AM
Unknown Object (File)
Wed, Apr 3, 8:03 AM
Unknown Object (File)
Sat, Mar 30, 10:54 AM
Unknown Object (File)
Mar 10 2024, 10:16 AM
Unknown Object (File)
Feb 6 2024, 10:56 AM
Unknown Object (File)
Feb 3 2024, 4:31 AM
Subscribers

Details

Summary

Fixes T4358. User request from IRC, but I think this is generally reasonable.

Although we can not prevent users from determining that other user accounts exist in the general case, it does seem reasonable to restrict browsing the user directory to a subset of users.

In our case, I'll probably do this on secure.phabricator.com, since it seems a little odd to let Google index the user directory, for example.

Test Plan

Set the policy to "no one" and tried to browse users.

Diff Detail

Lint
Lint Skipped
Unit
Tests Skipped