Merge pull request #1817 from aladh/patch-1

Prevent unauthorized access to feeds with a single subscriber
This commit is contained in:
Samuel Clay 2023-11-07 20:37:27 -05:00 committed by GitHub
commit 67b1041401
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -671,6 +671,10 @@ def load_single_feed(request, feed_id):
if feed.is_newsletter and not usersub:
# User must be subscribed to a newsletter in order to read it
raise Http404
if feed.num_subscribers = 1 and not usersub:
# This feed could be private so user must be subscribed in order to read it
raise Http404
if page > 400:
logging.user(request, "~BR~FK~SBOver page 400 on single feed: %s" % page)