System Addressbook does not respect "Restrict users to only share with users in their groups" sharing option
Nobody has claimed this yet.
- Dominant language
- PHP
- Stars
- 36.9k
- Forks
- 5.2k
- Avg merge
- 2d 3h
- Merged PRs (30d)
- 713
Description
Describe the bug
Hello team,
it's probably not considered a bug. But to operators like me, a serious issue.
I've just noticed that a system address book has been introduced some versions ago. Generally, I appreciate this feature. There is just one thing that annoys me on it: It doesn't respect the setting "Restrict users to only share with users in their groups.". This option has also limited the visibility of users that aren't within the same groups. This is a serious privacy setting on some of the instances that I manage. It's the only way to isolate core members from guests. Now with the system address book, it's suddenly possible to discover all other users again.
Steps to reproduce
Have two groups of users and the setting "Restrict users to only share with users in their groups." enabled.
Expected behavior
From my point of view, there should be one of these two options. The system address book …
- … can be disabled globally
- … respects the aforementioned setting
Actual behavior
Every user on the instance is visible in the address book.
Contact version
5.5.1
Operating system
27.1.3
PHP engine version
None
Web server
Apache (supported)
Database
MariaDB
Additional info
No response
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by reproducing the issue with two user groups and "Restrict users to only share with users in their groups" enabled, then inspect the system address book behavior. Done means the address book either can be disabled globally or hides users outside the current user's groups while preserving the privacy setting.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- php
- Domain
- authorization
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100