Comments
3 total
+1
[Security] Password reset page lacks https
6 years, 10 months ago
Looks like for now default password reset page (the one that is the user redirected to in email and requites to enter the new password) lacks https, so new user password is sent in plaintext and can be read by …
+1
[Security] Reading staff conversation as non admin.
7 years ago
... looks like now I can only "Quote" my own messages, and not the messages of other users (forum Quote button is useless for now).
Instead I think user should be able to Quote any message (written by any …
+2
[Security] Reading staff conversation as non admin.
7 years ago
Hi!
It looks like you have an issue with authorization using "comments/quote" rest method.
As for now it allows non-admin users to get any comment message content (even from non-public staff/mod-talk/ sub-forum) by id.
For example message …