#10 Bypassing authorization

已關閉
sindre5 年之前建立 · 0 條評論

User privilege validation is mostly performed on the client side. In this case it allows outside users without project access to perform task-deliveries and accept tasks. This must be done by sending a plain HTTP request instead of interacting through the client web page.

User privilege validation is mostly performed on the client side. In this case it allows outside users without project access to perform task-deliveries and accept tasks. This must be done by sending a plain HTTP request instead of interacting through the client web page.
sindre 新增至Required fixes 里程碑 5 年之前
sindre added the
broken access control
label 5 年之前
sindre added the
bug
label 5 年之前
sindre added the
webpy
label 5 年之前
sindre5 年之前 關閉
登入 才能加入這對話。
Loading…
取消
儲存
尚未有任何內容