Skip to content

Limit /users to be admin only #192

@thebrucecgit

Description

@thebrucecgit

Leaving this here as a note. Feel free to ignore.

I think /users, /users/online, /users/newest (can still be accessed via direct link) should be limited to admin only.

  1. Privacy - I think it's a bit strange that any user can see all 2.5k+ users of the website, even if it's mostly harmless info.
  2. This might be the most resource-intensive request across the whole site, taking up to 5 seconds to respond (and will increase in future). Might be vulnerable to DDOS attacks?
  3. Not much point in having it anyways

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions