-
-
Notifications
You must be signed in to change notification settings - Fork 5.8k
Members removed from team/repository keep watches #3782
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Comments
This should be tagged with a security label and perhaps assigned a CVE. |
@mqudsi it will only show the wrong watch but there is no wrong permission. |
@lunny thanks, that's much better :) |
From what I could tell, removed members will still get notification e-mails (including the full comments) for issues etc. While the removed members do not have access to the repository anymore, they may still get information they should not get. |
Perhaps need to add security or priority label? |
Closed with #4201 |
Description
When removing members from a team, they lose access to the respective repositories but keep their watches on the repository. This allows them to receive notifications via e-mail even if they should not be able to access the repository.
Reproducer (see link above): I added lunny to the test team, gave the team access to the repository and then removed lunny again. He still has a watch on the repository.
The text was updated successfully, but these errors were encountered: