Anyone signed in can read any feed's items and files, a private feed's included #129
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Routes that take a feed or enclosure id do not check that the person asking subscribes to it:
Found 2026-10-05 while adding a preview of Directory feeds (#128): /api/feeds/human-nature-blog-feed/entries answered 25 items to an account that does not subscribe to it. Every account here is someone the admin let in, which limits who could, but not what they could see.
Fixed in
b86062b: entries, download-latest, /api/enclosures/{id} (download and delete) and /media/{id} answer 404 unless you subscribe to the feed. Deployed 2026-10-05: /api/feeds/human-nature-blog-feed/entries now answers 404 to an account that does not subscribe to it, while that account's own feeds, those inside an OPML included, and its files still answer. Flags and position on someone else's feed still write the asker's own state only, which leaks nothing, and are left alone.