Cockatrice/libcockatrice_network/libcockatrice/network/server/remote
BruebachL 27fb5e51de
[Security] Redact sensitive user data from client-visible responses (#7077)
The getUserInfo command for a user that is not currently online returned
the full database record, including the account id, the email address
and the stored client id, to any logged-in requester. Mirror the
redaction already applied to online users via copyUserInfo(): the id and
email are only ever exposed to the account owner, and the client id only
to moderators.

The buddy/ignore add-to-list event likewise returned the target user's
email address and client id to the requester. The list entry only needs
the public profile fields, so strip the email and client id from it as
well.

Co-authored-by: Lukas Brübach <Bruebach.Lukas@bdosecurity.de>
2026-08-08 17:32:39 +02:00
..
game [Networking] Doxygen (#7030) 2026-07-27 11:27:00 +02:00
CMakeLists.txt Turn Card, Deck_List, Protocol, RNG, Network (Client, Server), Settings and Utility into libraries and remove cockatrice_common. (#6212) 2025-10-09 07:36:12 +02:00
room_message_type.h Turn Card, Deck_List, Protocol, RNG, Network (Client, Server), Settings and Utility into libraries and remove cockatrice_common. (#6212) 2025-10-09 07:36:12 +02:00
server.cpp [Room][UserList] Introduce style delegate (#6981) 2026-06-26 20:52:24 -04:00
server.h [Room][UserList] Introduce style delegate (#6981) 2026-06-26 20:52:24 -04:00
server_abstractuserinterface.cpp style: Add braces to all control flow statements (#6887) 2026-05-16 19:19:53 +02:00
server_abstractuserinterface.h [Cleanup] Unused #includes (#6367) 2025-11-29 18:53:11 +01:00
server_database_interface.cpp Turn Card, Deck_List, Protocol, RNG, Network (Client, Server), Settings and Utility into libraries and remove cockatrice_common. (#6212) 2025-10-09 07:36:12 +02:00
server_database_interface.h [Fix-Warnings] Remove more redundant empty declarations. (extra semicolons) (#6374) 2025-11-29 14:19:11 +01:00
server_player_reference.h fix arch compiling (#6895) 2026-05-16 19:39:34 +02:00
server_protocolhandler.cpp [Security] Redact sensitive user data from client-visible responses (#7077) 2026-08-08 17:32:39 +02:00
server_protocolhandler.h [Cleanup] Unused #includes (#6367) 2025-11-29 18:53:11 +01:00
server_remoteuserinterface.cpp Turn Card, Deck_List, Protocol, RNG, Network (Client, Server), Settings and Utility into libraries and remove cockatrice_common. (#6212) 2025-10-09 07:36:12 +02:00
server_remoteuserinterface.h Turn Card, Deck_List, Protocol, RNG, Network (Client, Server), Settings and Utility into libraries and remove cockatrice_common. (#6212) 2025-10-09 07:36:12 +02:00
server_response_containers.cpp style: Add braces to all control flow statements (#6887) 2026-05-16 19:19:53 +02:00
server_response_containers.h Mark more functions as [[nodiscard]] (#6320) 2025-11-16 01:39:24 +01:00
server_room.cpp Split trice_limits.h into dedicated headers (#7025) 2026-06-29 14:37:52 -07:00
server_room.h [Cleanup] Unused #includes (#6367) 2025-11-29 18:53:11 +01:00
serverinfo_user_container.cpp style: Add braces to all control flow statements (#6887) 2026-05-16 19:19:53 +02:00
serverinfo_user_container.h Mark more functions as [[nodiscard]] (#6320) 2025-11-16 01:39:24 +01:00
user_level.h Turn Card, Deck_List, Protocol, RNG, Network (Client, Server), Settings and Utility into libraries and remove cockatrice_common. (#6212) 2025-10-09 07:36:12 +02:00