Skip to content
This repository was archived by the owner on Sep 24, 2018. It is now read-only.

Conversation

@rmccue
Copy link
Member

@rmccue rmccue commented Jul 26, 2015

Just now in #1397, we added the ability to list users with published posts at /wp/v2/users. Problem is, right now, it's exposing all user data (context=view), but users should only be able to access context=embed

Merging now to avoid security issues, but we can fix up the handling later.

cc @joehoyle

@rmccue rmccue added the Bug label Jul 26, 2015
@rmccue rmccue added this to the 2.0 Beta 4 milestone Jul 26, 2015
@rmccue
Copy link
Member Author

rmccue commented Jul 26, 2015

Oh, also, forgot to mention! Major props to @Shelob9 for noticing this one and notifying me immediately. ✨

@rmccue rmccue self-assigned this Jul 26, 2015
rmccue added a commit that referenced this pull request Jul 26, 2015
Don't expose non-public user information in the collection
@rmccue rmccue merged commit ba64cdb into develop Jul 26, 2015
@rmccue rmccue deleted the fix-user-visibility branch July 26, 2015 19:54
@joehoyle
Copy link
Member

Doh! Apologies for that

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants