I have checked the userinfo.json response in my project.
On prod author as we do have SSO, I could see certain information about myself (logged-in user) while accessing /libs/cq/security/userinfo.json.
On prod publish we aren't supposed to login so, I can see anonymous while accessing /libs/cq/sec...