Skip to content

Public repositories of a private organization are hidden but can be checked out by anyone #6491

@lightoze

Description

@lightoze

Relevant to #6234

  • Gitea version (or commit ref): 1.8.0 (docker image)

On UI side such repository is protected from user access which gives false sense of security, because any authenticated user (anonymous not tested) can still check it out.

Metadata

Metadata

Assignees

No one assigned

    Labels

    topic/securitySomething leaks user information or is otherwise vulnerable. Should be fixed!type/bug

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions