Skip to content

虚假的安全认证的保护 #353

Open
@amsz

Description

@amsz

Describe the bug

版本 v2.3.1

使用 AUTH_PASSWORD 方式运行后点击开始调试,跳转的链接为 http://127.0.0.1:6752/#/room-list,界面提示输入密码。

但是修改访问链接,例如 http://127.0.0.1:6752/aa#/room-list,就可以任意访问了。

Steps to reproduce

No response

System Info

Ubuntu 20.04.6 LTS

Logs

No response

Validations

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions