trackslash
TRACK-21 P2

Stop autofilling usernames when adding project members

0
All issues

Description

Problem

Autofilling or suggesting usernames before the user has intentionally searched can disclose the existence and identity of other accounts.

Acceptance criteria

  • The add-member form starts with an empty username field and no candidate list.
  • Opening or focusing the field does not fetch or display usernames.
  • Candidate lookup begins only after the project owner enters an intentional search query of an appropriate minimum length.
  • Results are limited, scoped to users eligible for membership, and do not expose unnecessary profile data.
  • Empty, whitespace-only, and too-short queries return no candidates.
  • Direct submission of a known exact username remains supported and is validated server-side.
  • Add UI and endpoint tests proving no usernames are returned before an intentional query and authorization is still enforced.

Sub-issues

0

Linked issues

0

GitHub

0

No branches or pull requests linked.

Comments

2
Bradley

Completed and merged via PR #106 (d158953056060d5924882757054f24f56cb18066).

Implemented:

  • removed the eager, empty-query candidate lookup from the project member page
  • added debounced, query-driven UI candidate results that stay closed on focus
  • required at least two trimmed characters for UI, REST, store, and MCP candidate searches
  • capped candidate responses at 10 safe identity records
  • preserved exact username submission and server-side validation
  • added blank/whitespace/short-query, authorization, safe-field, result-limit, render, and MCP coverage

Validation: full make test passed against Postgres, go vet ./... passed, and both required GitHub checks passed.

Bradley

Started work on codex/track-21-private-member-search. I’m tightening the add-member flow so it returns no account candidates until an authorized owner/admin submits a trimmed query of the minimum supported length, while preserving exact username submission.