Shortcut is a core module installed by default when using Standard profile. So that it is quite easy to figure out if a user with a given ID registered on a site.
Shortcut is a core module installed by default when using Standard profile. So that it is quite easy to figure out if a user with a given ID registered on a site.
Comments
Comment #2
nicksanta commented#2133887: Enumeration still possible through user pages added all routes using the user entity link template. This should include the shortcut module's routes.
Have you tested this on the 8.x-1.0 release?
Comment #3
nicksanta commentedComment #4
chi commentedThose routes do not have registered links on user entity. I've just tested on 1.0. The issue still exist.
Comment #6
nicksanta commentedFix merged in https://github.com/nicksantamaria/drupal-username_enumeration_prevention... - thanks for the report @Chi!