security: ensure users cannot add themselves to clubs and teams #63

Closed
opened 2025-05-25 19:26:44 +00:00 by Obnoxieux · 1 comment
Obnoxieux commented 2025-05-25 19:26:44 +00:00 (Migrated from github.com)

for current single-tenant usage the risk is negligible, but for wider rollout this is a massive security issue

for current single-tenant usage the risk is negligible, but for wider rollout this is a massive security issue
Obnoxieux commented 2025-05-25 21:25:25 +00:00 (Migrated from github.com)

clubs deactivated via PB API rule, needs more thorough testing and preferably Go test

clubs deactivated via PB API rule, needs more thorough testing and preferably Go test
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
tib-baseball/skylarks-diamond-planner#63
No description provided.