Skip to content

Security vulnerability: the userIds of all users in a room are exposed #72

@alankbi

Description

@alankbi

If you inspect element and go to either console or network, the userId of every user in a room is exposed (through both REST requests and through socket messages). Basically, that means anyone can send in host-only requests as well as delete random users (if we re-add in the delete users endpoint)

Metadata

Metadata

Assignees

No one assigned

    Labels

    bug fixSomething isn't working

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions