Skip to content

Fix public token bypassing request prominence#9186

Merged
sagepe merged 1 commit intodevelopfrom
fix-public-token-hidden-request-access
Mar 27, 2026
Merged

Fix public token bypassing request prominence#9186
sagepe merged 1 commit intodevelopfrom
fix-public-token-hidden-request-access

Conversation

@gbp
Copy link
Copy Markdown
Member

@gbp gbp commented Mar 26, 2026

Public tokens bypassed InfoRequest prominence checks in ability model.

Restrict the public token ability so it only grants access when the request has "normal" or "backpage" prominence.

This change matches the intended use case of sharing embargoed requests without bypassing prominence.

Public tokens bypassed `InfoRequest` prominence checks in ability model.

Restrict the public token ability so it only grants access when the
request has "normal" or "backpage" prominence.

This change matches the intended use case of sharing embargoed requests
without bypassing prominence.
@sagepe sagepe merged commit 231eac7 into develop Mar 27, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants