Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Check rights of Invite creator #182

Closed
3 of 4 tasks
joepio opened this issue Oct 3, 2021 · 0 comments
Closed
3 of 4 tasks

Check rights of Invite creator #182

joepio opened this issue Oct 3, 2021 · 0 comments

Comments

@joepio
Copy link
Member

joepio commented Oct 3, 2021

We recently introduced Invites #134

However, the current implementation makes it possible for users to grant themselves rights to edit things that aren't theirs. To prevent this, we need to perform these checks:

I think we need to check this twice, because after an invite has been created, the rights of the creator could have changed.

@joepio joepio added the security label Oct 3, 2021
@joepio joepio mentioned this issue Oct 3, 2021
7 tasks
@joepio joepio changed the title Limit Inivtes Check rights of Invite creator Oct 3, 2021
@joepio joepio added this to the v0.27 milestone Oct 3, 2021
@joepio joepio modified the milestones: v0.27, v0.28 Oct 25, 2021
joepio added a commit that referenced this issue Dec 11, 2021
joepio added a commit that referenced this issue Dec 11, 2021
@joepio joepio closed this as completed Dec 11, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant