Skip to content

AUTH-015: Add auth check to GET /auth/users/{user_id} #580

@lbedner

Description

@lbedner

Priority: Critical | Estimate: S

GET /auth/users/{user_id} returns user details (email, name, etc.) with no authentication. Anyone can enumerate user IDs and extract emails.

Fix

Add authentication requirement. Options:

  • Require auth token (any authenticated user can look up users)
  • Or restrict to admin/moderator + self

Acceptance Criteria

  • Endpoint requires authentication
  • Unauthenticated requests return 401
  • Tests cover authenticated and unauthenticated access

Metadata

Metadata

Assignees

No one assigned

    Labels

    authbugSomething isn't working

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions