hypothesis / hypothesis/product-backlog

privacy leak in activity pages

Open
#161 3 comments 0 reactions 0 assignees View on GitHub
activity pages
Dominant language
No language data
Stars
122
Forks
7
PR merge metrics
No merged PRs in 30d

Description

I just visited https://hypothes.is/search and saw this:

![image](https://cloud.githubusercontent.com/assets/46509/22610080/91966d8e-ea18-11e6-8114-96fe9d16881b.png)

A link was exposed to https://hypothes.is/groups/eixQ87nL/educ661ol-sp-17. I am not a member of that group, so following the link yields:

![image](https://cloud.githubusercontent.com/assets/46509/22610104/afdfc10a-ea18-11e6-8883-73eba3c7bf6e.png)

Should not happen.

We've seen this before, there may be another issue filed for it, but anyway, the problem is that the groups page itself was annotated in public. Not sure if we agreed on a solution last time we noticed this. We could perhaps treat group URLs annotated in public as if they were URLs belonging to the group? And/or prevent it with a warning: "You are annotating a group page in Public, this will reveal the secret invitation link, are your sure you want to do that?"

Contributor guide

No contributing guide indexed for this repository

Research direction

Reproduce the exposure from https://hypothes.is/search and inspect the linked group URL, then review the issue's existing discussion for the unresolved solution. Done means a public activity page no longer reveals a private group invitation URL, with any warning or access behavior matching the agreed resolution.

Written by the indexing model from the issue text.

Assessment

Domain
security
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.