This repository was archived by the owner on Jul 15, 2025. It is now read-only.
User can see invitees in events created in PMs and private categories
Package
No package listed
Affected versions
<= 0.3
Patched versions
>= 0.4
Impact
Event invitees created in topics in private categories or PMs (private messages) can be retrieved by anyone, even if they're not logged in.
Patches
This problem is resolved in the latest version of the discourse-calendar plugin
Workarounds
No real workaround.
Putting the site behind
login_required
will disallow this endpoint to be used by anonymous users, but logged in users can still get the list of invitees in the private topics.