Skip to content

Private group names are exposed to non-members - Groups tab

  1. Create a public project
  2. Go to Members page. Invite a group, select a private group
  3. Log out. Go to the members page. You can see the private group name in the Groups tab

Screenshot_2023-06-13_at_9.56.50_PM

What I see

The private group name, and path is shown on the Members page

What I expect to see

The private group is now shown at all on the Members page for unauthorized users or users without access to the private group.

Here are the mockups from @ameliabauerly (#387603 (comment 1446372784), #387603 (comment 1447280926)):

Group tab: image

Implementation plan

/cc @lohrc @gitlab-com/gl-security/appsec @alexpooley @lciutacu

Edited by Thong Kuah