-
Notifications
You must be signed in to change notification settings - Fork 4
Open
Description
The GET /years endpoint (https://rest.ksi.fi.muni.cz/years) currently exposes the following properties:
sum_points: Includes points for tasks that have not yet been released.tasks_cnt: Includes a count of tasks that have not yet been released.
This behavior allows anyone to deduce how many tasks are unreleased and the potential points they might earn from these tasks.
Steps to Reproduce
- Access the endpoint
https://rest.ksi.fi.muni.cz/yearswithout any specific restrictions or permissions. - Observe that the response includes the properties
sum_pointsandtasks_cntwith values reflecting both released and unreleased tasks (e.g., there is a greater number of tasks than the user can see).
Expected Behavior
- The properties
sum_pointsandtasks_cntshould only account for tasks that are already released. - Unreleased tasks should not influence the response data in any way.
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels