Via HackerOne. I don't think this is a security vulnerability, but it is inconsistent. There's no reason to prefill this, and I think the code was just lazy.
Details
Details
- Reviewers
btrahan - Commits
- Restricted Diffusion Commit
rP761b66228371: Don't prefill "add email address" from GET
- Hit this page with ?email=xyz in a GET request, no more prefill.
- Looped the page with bad addresses, appropriate prefill.
- Added an address.
Diff Detail
Diff Detail
- Repository
- rP Phabricator
- Lint
Lint Skipped - Unit
Tests Skipped