Hi,
As Administrator, I setup a RoleA which full access on DoctypeA and create/assign some users to it (User1, User2…).
Logout Administrator, and Login with User1,
I observed that, User1 can access and see the list of Users when I copy and paste the url to browser, ex: https://somedomain/app/user
Expected User1 just only see data in DoctypeA list, and get access denied if go anywhere else.
This seems to be critical.
Please anyone get similar issue?
So, In my opinion, Frappe may should not set that mapping for all as default.
Because administrator may forget to remove that, then someone can see all users (with fullname, phone, email… which show on list) that leads to an information leak.