Uploaded image for project: 'Bitbucket Cloud'
  1. Bitbucket Cloud
  2. BCLOUD-8368

API leaks information about private wiki and issue tracker (BB-9521)

    XMLWordPrintable

Details

    Description

      The repositories API reports that a repository has an issue tracker even if the tracker is private and it's an unauthenticated party making the request. Same goes for the wiki.

      Example: https://bitbucket.org/api/1.0/repositories/ZeroOne3010/simple-rss-parser says "has_issues": true, whereas you cannot see the issue tracker when looking at the corresponding web page: https://bitbucket.org/ZeroOne3010/simple-rss-parser

      I would expect the API to report that no issue tracker or wiki is present unless the requested actually has an access to them. It even says in the issue tracker and wiki settings, under the 'Private' option, that they are "visible only to people who have repository access".

      Attachments

        Activity

          People

            Unassigned Unassigned
            0b203213071f Ville Saalo
            Votes:
            1 Vote for this issue
            Watchers:
            2 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: