• Aaron Wells's avatar
    For private profiles, hide all profile information from logged-out users · 6490dda9
    Aaron Wells authored
    Bug1158625: If the user hasn't made their profile public, don't even show their pic and name
    to logged-out users.
    
    And in order to prevent enumeration attacks, show the same access denied screen to a
    logged-out user, whether they hit the URL for an exising profile or whether they entered
    an invalid URL.
    
    Change-Id: Ic926fde3e04a59728868fffecc9272136fb83855
    6490dda9
view.php 14 KB