Skip to content

Enforce unique userIds and userNames #72

@HerbCaudill

Description

@HerbCaudill

It's possible that I can currently join a team with an existing user's id and then impersonate them. Need to test this to be sure.

A "softer" attack would be to join a team with an existing user's user name, which is definitely possible, and could cause confusion.

The tricky part here would be to sort out collisions that happen concurrently.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions