Skip to content

Conversation

@akshayutture-augment
Copy link

@akshayutture-augment akshayutture-augment commented Nov 14, 2025

Test 6


Replicated from ai-code-review-evaluation/discourse-cursor#6


Note

Adds server-computed website_name to user JSON and updates the profile header to use it, showing host or full path based on relation to the instance domain.

  • Backend:
    • UserSerializer: add website_name with logic to return host or full path depending on instance domain; include only when website is present.
    • Tests: extend user_serializer_spec to validate website_name for different domain scenarios; adjust website fixture to include path.
  • Frontend:
    • templates/user/user.hbs: replace websiteName with model.website_name in the user header link/text.
    • controllers/user.js.es6: remove websiteName computed property.
    • models/user.js.es6: fix JSDoc tag for profileBackground.

Written by Cursor Bugbot for commit 267d8be. Configure here.

@akshayutture-augment
Copy link
Author

cursor review


def include_website_name
website.present?
end
Copy link

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Bug: Privacy Bypass: Derived Field Exposed

The include_website_name method doesn't check scope.restrict_user_fields?(object) like other untrusted attributes. This causes website_name to be visible for TL0 users viewed by anonymous users, even though website is properly hidden. Since website_name is derived from website, it should respect the same privacy restrictions.

Fix in Cursor Fix in Web

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants