Skip to content

[Parent] Public API exposes reviewer emails and allows bulk extraction #326

Description

@jenul-ferdinand

What

Tracking issue for five fixes that stop the public API leaking user data and make bulk extraction of reviews expensive and off-limits. Each fix has its own issue:

Why

  • GET /api/v2/reviews/popular?n=<large> returns every review with the author's full user document: email, googleID, admin flag, vote history and refresh-token hash. The route has no auth and no cap on n.
  • The unit page requests populateReviewsAuthor=true (unit-overview.component.ts), so every visitor's browser downloads the email of every reviewer on that unit.
  • GET /api/v2/units embeds every review for every unit in one response.
  • GET /api/v2/users/:username strips tokens but returns email, admin and vote history. Usernames default to the first eight characters of the email.
  • The backend has no rate limiting.
  • The refresh-token hash is SHA-256 of a random token read from an httpOnly cookie, so an attacker cannot use it as a credential. It should not be public either.

Area

backend, frontend, infra, database

Notes or constraints

  • Per-unit review reads stay public because that is the product. After the first two fixes, what is public matches what the site shows: review text, ratings, username and profile image.
  • The first two fixes fit in one PR. The last one is dashboard work with no PR.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

backenddatabaseMongoDB schema, indexes, migrations, queries, and data integrity.frontendinfraDeployment, Vercel config, CI/CD, env vars, and build pipeline.priority: highUrgent. Fix or ship before other work: broken prod, security, or blocking bugs.securityVulnerabilities, leaked secrets, auth flaws, dependency CVEs, or hardening.

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions