zmacr's avatar

zmacr

LV.2
15/20 XP
Joined March 2019 3 posts 35 XP 40 achievement pts

Comments

3 total
+1
[Security] Password reset page lacks https

Looks like for now default password reset page (the one that is the user redirected to in email and requites to enter the new password) lacks https, so new user password is sent in plaintext and can be read by …

6 years, 10 months ago
+1
[Security] Reading staff conversation as non admin.

... looks like now I can only "Quote" my own messages, and not the messages of other users (forum Quote button is useless for now).

Instead I think user should be able to Quote any message (written by any …

7 years ago
+2
[Security] Reading staff conversation as non admin.

Hi!

It looks like you have an issue with authorization using "comments/quote" rest method.

As for now it allows non-admin users to get any comment message content (even from non-public staff/mod-talk/ sub-forum) by id.

For example message …

7 years ago