RealDevSquad / RealDevSquad/website-backend
Unwanted Privileges Concerns of Syncing All Groups from Discord to Database
Nobody has claimed this yet.
- Dominant language
- JavaScript
- Stars
- 74
- Forks
- 276
- Avg merge
- 1d 26m
- Merged PRs (30d)
- 14
Description
Issue Description
This PR (- #1558 ) introduces functionality to sync all discord roles data (id, created by, timestamps) and this has unwanted privileges concerns. This features syncs all roles including roles with permissions (eg. admin, mod). These roles are then available to be added/removed to self in discord via dashboard site.
Screenshots
Severity/Priority
- Critical
- High
- Medium
- Low
Additional Information
Checklist
- I have read and followed the project's code of conduct.
- I have searched for similar issues before creating this one.
- I have provided all the necessary information to understand and reproduce the issue.
- I am willing to contribute to the resolution of this issue.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Review PR #1558 and trace how Discord roles, including their permissions, are synced to the database and exposed through the dashboard site. Confirm that roles with administrative or moderation permissions cannot be made available for self-assignment or removal, and verify the behavior through the relevant syncing and dashboard flows.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- javascript, node.js
- Domain
- authorization, backend, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100