hypothesis / hypothesis/product-backlog
privacy leak in activity pages
- Dominant language
- No language data
- Stars
- 122
- Forks
- 7
- PR merge metrics
- No merged PRs in 30d
Description
I just visited https://hypothes.is/search and saw this:

A link was exposed to https://hypothes.is/groups/eixQ87nL/educ661ol-sp-17. I am not a member of that group, so following the link yields:

Should not happen.
We've seen this before, there may be another issue filed for it, but anyway, the problem is that the groups page itself was annotated in public. Not sure if we agreed on a solution last time we noticed this. We could perhaps treat group URLs annotated in public as if they were URLs belonging to the group? And/or prevent it with a warning: "You are annotating a group page in Public, this will reveal the secret invitation link, are your sure you want to do that?"
Contributor guide
No contributing guide indexed for this repository
Research direction
Reproduce the exposure from https://hypothes.is/search and inspect the linked group URL, then review the issue's existing discussion for the unresolved solution. Done means a public activity page no longer reveals a private group invitation URL, with any warning or access behavior matching the agreed resolution.
Written by the indexing model from the issue text.
Assessment
- Domain
- security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100