El correo electrónico del usuario no está oculto en el área de Single Sign On de la página de administración.

When viewing a User on the admin/users page the Primary Email and Secondary Email fields are hidden, and require permissions to view:

image

But the same email is shown unprotected when using SSO further down the page:

Expected: SSO Email is protected like the Primary and Secondary emails.

Actual: SSO Email is not protected, and visible to moderators even when site settings forbid showing emails to moderators.

One more comment, I mentioned email but really even the External ID can be sensitive info too.

2 Me gusta

I’m not sure if this qualifies as a bug, but it’s definitely an issue that needs to be addressed.

3 Me gusta

Fixed via:

5 Me gusta

@anon60302432 brought into our notice that SSO payload includes email as well so we’ve hidden the payload behind a button click as well, via:

3 Me gusta