SECURITY: Ok for `keypod` to access data of `podnotes` in the same POD?
Open
Nobody has claimed this yet.
- Dominant language
- Dart
- Stars
- 10
- Forks
- 7
- Avg merge
- 1d 3h
- Merged PRs (30d)
- 6
Description
A user logged in the keypod app (in theory) can access any data in the podnotes directory in the same POD.
Is this okay from a security perspective? (Noted that all data in the POD do belong to the same user).
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
The issue names the keypod app and the podnotes directory but no source files, tests, or entry points. Start by tracing how a logged-in keypod user accesses data in the same POD, then establish the intended permission boundary and document or test the security decision.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- dart
- Domain
- authorization, security
- Issue type
- Bug
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100