非论坛员工收到仅限员工标签的通知

It seems a non-staff member can get notifications if they are ‘watching’ a tag even though that tag is restricted to staff only (read/write).

A little backstory:

I recently left a group that I was involved in as a moderator. We used tags internally to help track important topics, some of these tags were set up so only staff could see and add them. So I was aware of these topics I had set my notification settings to ‘Watching First Post’ for the staff-only tags.

Now that I am no longer a staff member I still get notifications when the tag is applied to a topic. However, I cannot:

  • Access the tag page /tags/{tag_name}
  • See the tag on the topic
  • See that the topic was edited by a staff member to add the tag
  • Once I remove that tag from my notification preferences, I cannot add it back

Because I cannot access, or see the tag, I don’t think I should be able to get notifications when it is applied. I wouldn’t consider this to be a security issue per se, but it could potentially leak some information some communities don’t want to be known outside of their staff team(s).

8 个赞

您好,感谢您的反馈。我们已将修复程序推送到最新版本。这样您应该:

  • 停止接收您之前关注的特权标签的通知
  • 甚至不会在通知偏好设置中看到这些标签,也无需取消关注它们
    • 这部分的好处是,如果您被重新任命为版主,您将不必重新关注它们!

PR:SECURITY: Only show tags to users with permission by nattsw · Pull Request #15148 · discourse/discourse · GitHub

2 个赞