mirror of
https://github.com/discourse/discourse.git
synced 2025-02-10 21:34:50 +00:00
245d29e5a3
Moderators should not be able to see `UserSerializer#group_users` and `UserSerializer#second_factor_enabled` of other users. Impact of leaking this is low because the information leaked is not exploitable.