fix(api): hide limited users from restricted viewers (#39004)

Use the canonical profile-visibility check for user API content and
prevent restricted users from enumerating public repositories owned by
limited users.

This keeps feeds, heatmaps, keys, and issue search consistent with
profile visibility.

---------

Co-authored-by: silverwind <me@silverwind.io>
This commit is contained in:
bircni
2026-08-22 10:08:36 +02:00
committed by GitHub
parent f7072b0305
commit 6bb6ce678b
4 changed files with 84 additions and 25 deletions
+1 -1
View File
@@ -221,7 +221,7 @@ func applyRepoConditions(sess db.Session, opts *IssuesOptions) {
if opts.RepoCond == nil {
opts.RepoCond = builder.NewCond()
}
opts.RepoCond = opts.RepoCond.Or(builder.In("issue.repo_id", builder.Select("id").From("repository").Where(builder.Eq{"is_private": false})))
opts.RepoCond = opts.RepoCond.Or(builder.In("issue.repo_id", builder.Select("id").From("repository").Where(repo_model.PublicRepoUnderPublicOwnerCond())))
}
if opts.RepoCond != nil {
sess.And(opts.RepoCond)
+3 -9
View File
@@ -652,18 +652,12 @@ func SearchRepositoryIDsByCondition(ctx context.Context, cond builder.Cond) ([]i
Find(&repoIDs)
}
func userAllPublicRepoCond(cond builder.Cond, orgVisibilityLimit []structs.VisibleType) builder.Cond {
func userAllPublicRepoCond(cond builder.Cond, ownerVisibilityLimit []structs.VisibleType) builder.Cond {
return cond.Or(builder.And(
builder.Eq{"`repository`.is_private": false},
// Exclude owners who are not visible to the caller.
builder.NotIn("`repository`.owner_id", builder.Select("id").From("`user`").Where(
builder.Or(
builder.And(
builder.Eq{"type": user_model.UserTypeOrganization},
builder.In("visibility", orgVisibilityLimit)),
builder.And(
builder.Neq{"type": user_model.UserTypeOrganization},
builder.Neq{"visibility": structs.VisibleTypePublic}),
),
builder.In("visibility", ownerVisibilityLimit),
))))
}