Alan Guo Xiang Tan 42d2cb2d4e
SECURITY: Hide PM count for tags by default (#20061) (#20090)
Currently `Topic#pm_topic_count` is a count of all personal messages tagged for a given tag. As a result, any user with access to PM tags can poll a sensitive tag to determine if a new personal message has been created using that tag even if the user does not have access to the personal message. We classify this as a minor leak in sensitive information.

With this commit, `Topic#pm_topic_count` is hidden from users by default unless the `display_personal_messages_tag_counts` site setting is enabled.
2023-02-01 06:43:58 +08:00
..
2023-01-24 16:32:59 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-24 16:32:59 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-24 16:32:59 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-24 16:32:59 +01:00
2023-01-24 16:32:59 +01:00
2023-01-10 20:53:34 +01:00
2023-01-31 15:21:19 +01:00
2023-01-18 11:42:57 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-24 16:32:59 +01:00
2023-01-31 15:21:19 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-31 15:21:19 +01:00
2023-01-18 11:42:57 +01:00
2023-01-31 15:21:19 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-24 16:32:59 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-24 16:32:59 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-24 16:32:59 +01:00
2023-01-10 20:53:34 +01:00
2023-01-31 15:21:19 +01:00
2023-01-31 15:21:19 +01:00
2023-01-31 15:21:19 +01:00
2023-01-31 15:21:19 +01:00
2023-01-31 15:21:19 +01:00
2023-01-10 20:53:34 +01:00
2023-01-31 15:21:19 +01:00
2023-01-31 15:21:19 +01:00
2023-01-31 15:21:19 +01:00
2022-12-09 12:01:05 +01:00
2023-01-31 15:21:19 +01:00
2023-01-10 20:53:34 +01:00
2023-01-31 15:21:19 +01:00
2023-01-31 15:21:19 +01:00
2023-01-31 15:21:19 +01:00
2023-01-31 15:21:19 +01:00
2023-01-31 15:21:19 +01:00
2023-01-18 11:42:57 +01:00
2023-01-10 20:53:34 +01:00
2023-01-31 15:21:19 +01:00
2023-01-10 20:53:34 +01:00
2023-01-31 15:21:19 +01:00
2023-01-31 15:21:19 +01:00
2023-01-31 15:21:19 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-31 15:21:19 +01:00
2023-01-31 15:21:19 +01:00
2023-01-31 15:21:19 +01:00
2023-01-31 15:21:19 +01:00
2023-01-31 15:21:19 +01:00
2023-01-31 15:21:19 +01:00
2023-01-31 15:21:19 +01:00
2023-01-10 20:53:34 +01:00
2023-01-31 15:21:19 +01:00
2023-01-10 20:53:34 +01:00
2023-01-31 15:21:19 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-10 20:53:34 +01:00
2023-01-31 15:21:19 +01:00
2023-01-31 15:21:19 +01:00
2023-01-31 15:21:19 +01:00
2023-01-31 15:21:19 +01:00
2023-01-31 15:21:19 +01:00
2023-01-31 15:21:19 +01:00
2017-02-24 11:35:33 +01:00