-
-
Notifications
You must be signed in to change notification settings - Fork 218
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
🐛 Check in List Browseable without any Authentication #312
Comments
Hi @jameskitt616, This is by design as many event organizers want to quickly share the check-in tool with staff/volunteers without needing to create accounts. While it may seem insecure, the random ID in the URL (e.g I hope this explanation puts your mind at ease. |
I do understand why this decision was made and why and how valuable this is to some. I would suggest some middle way: The threat isn't purely on trying to brute-force the random ID for the list. Also: Thank you very much for the fast response. The tool is absolutely amazing! Keep it up. |
That's a valid point! Currently the only way to disable access is to delete the list, which isn't ideal. I'll try to fir this change into the upcoming v1 release. Thanks again. |
Describe the bug
The Created Checkin Lists are Viewable/Editable without any Verification or Login.
Anybody who knows the URL can just Check-In or Out anybody and view the person's full Name etc.
To Reproduce
Steps to reproduce the behavior:
Expected behavior
Even with knowing the Link of the Check-In list, it only should be possible to View/Browse/Edit it being Authenticated as Admin or Oraganizer.
Desktop (please complete the following information):
Hi.Events Version and platform
Docker v0.8.0-beta.6
The text was updated successfully, but these errors were encountered: