Leaving this here as a note. Feel free to ignore.
I think /users, /users/online, /users/newest (can still be accessed via direct link) should be limited to admin only.
- Privacy - I think it's a bit strange that any user can see all 2.5k+ users of the website, even if it's mostly harmless info.
- This might be the most resource-intensive request across the whole site, taking up to 5 seconds to respond (and will increase in future). Might be vulnerable to DDOS attacks?
- Not much point in having it anyways
Leaving this here as a note. Feel free to ignore.
I think
/users,/users/online,/users/newest(can still be accessed via direct link) should be limited to admin only.