Skip to content

After an abuse report, redirect to root instead of user profile

Dominic Couture requested to merge abuse-redirect-root into master

What does this MR do?

Fixes https://gitlab.com/gitlab-org/gitlab/-/issues/23175

This closes a user enumeration vector. We have plenty of those by design but I'm reviewing old security issues and even if user enumeration is an accepted risk redirecting to root seemed like the preferred behavior anyway and a very simple change.

Screenshots (strongly suggested)

Does this MR meet the acceptance criteria?

Conformity

Availability and Testing

Security

Does this MR contain changes to processing or storing of credentials or tokens, authorization and authentication methods or other items described in the security review guidelines? If not, then delete this Security section.

  • Label as security and @ mention @gitlab-com/gl-security/appsec
  • The MR includes necessary changes to maintain consistency between UI, API, email, or other methods
  • Security reports checked/validated by a reviewer from the AppSec team
Edited by Dominic Couture

Merge request reports

Loading