Restrict Remove Friend controls to the signed-in user’s own friend lists #33
Labels
No labels
automated
code-quality
component: admin dashboard
component: backend
component: billing
component: content management
component: faqs
component: game genres
component: game lists
component: game reviews
component: game search
component: games
component: internal notifications
component: platforms
component: security
component: tests
component: user api
component: user badges
component: user blogs
component: user consoles
component: user favorites
component: user friends
component: user notifications
component: user profiles
component: user site notifications
component: user wishlists
component: web design
dependencies
php
priority
high
priority
low
priority
medium
security-hotspot
source: codex
source: sonarqube
status
awaiting feedback
status
backlog
status
done
status
in progress
status
in queue
status
in review
status
needs codex review
status
needs investigation
status
wontfix
type: bug
type: documentation
type: feature
type: improvement
type: regression
type: task
No milestone
No project
No assignees
2 participants
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
MyVideoGameList/myvideogamelist.com#33
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Friend action ownership needs to be rebuilt so authenticated users cannot see or use Remove Friend controls while viewing another user's Friends or Friends Of pages.
The original issue reported that a signed-in user could see Remove Friend on a friend list that was not theirs. The rebuilt friending feature now enforces ownership through the user_friends model, authenticated mutation routes, profile-only friend actions, and read-only Friends/Friends Of list pages.
Scope
Acceptance Criteria
Test Coverage Required
Progress Checklist
Hide ''Remove Friend'' on other users friend liststo Restrict Remove Friend controls to the signed-in user’s own friend listsReviewed against the rebuilt friending feature from issue #55 and this is now covered.
Evidence:
Verification run: