I wasn’t sure how to report this as an issue given the documentation links.
If you just type the full URL to the Things view, OH3 will list all of them even if you aren’t logged in and aren’t supposed to see settings. I haven’t tried with other views but it seems that this should be denied? In the screenshot below you can see that I am not logged in yet I can get to the Things view.
The view was accessible as http:/hostname.local/#!/settings/things/ with hostname being the hostname of my Pi.