Closed Bug 689338 Opened 14 years ago Closed 14 years ago

Unvouched users can access search page and search for their own profile

Categories

(Participation Infrastructure :: Phonebook, defect, P3)

x86
macOS
defect

Tracking

(Not tracked)

VERIFIED FIXED

People

(Reporter: Tobbi, Assigned: tofumatt)

Details

Nice feature: As an unvouched user, I can go to https://mozillians.allizom.org/en-US/search and search for my own profile. Which can be very useful in case you forgot that you exist. Uuh, whatever.... I believe, we should find a better solution for that. https://mozillians.allizom.org/en-US/search
Users see this issue when doing something they're not supposed to. It'd be good to post a safeguard and clean up this negative test case with a redirect or easter egg.
Priority: -- → P3
This is a feature _request_, not a bug, right?
It's a bug as its a negative test case. Non-vouched logged-in users shouldn't be able to go to the search page whatsoever. Right now, it's just hidden and the functionality is nerfed, but the page still shows if you go to the URL. With that said, it's definitely not a high priority at all since it's such a small use case.
Well if non-vouched users shouldn't see the search page at all, I can fix that. But I'm not marking it for 1.0. If I can get it out the door by then: great. But it's not likely at this point.
Assignee: nobody → tofumatt
Target Milestone: --- → 1.1
Yeah, that sounds good. Even if it falls out of 1.1, that's fine as well.
How's this https://github.com/mozilla/mozillians/commit/a56738d8b20df6d010f1a0780aaf0013dbea04ae? It now shows the generic error page; we can tweak what it says in future releases.
Status: NEW → RESOLVED
Closed: 14 years ago
Resolution: --- → FIXED
Target Milestone: 1.1 → 1.0
Verified unvouched users can't access search page.
Status: RESOLVED → VERIFIED
Component: mozillians.org → Phonebook
Product: Websites → Community Tools
QA Contact: mozillians-org → phonebook
Target Milestone: 1.0 → ---
Version: unspecified → other
You need to log in before you can comment on or make changes to this bug.