azerothcore / azerothcore/acore-node-server
Security issue on mutations
Open
- Dominant language
- JavaScript
- Stars
- 5
- Forks
- 2
- PR merge metrics
- No merged PRs in 30d
Description
Mutations of resend emails or passwords should ne denied if the user id is not equal to the requester id, it could be an easy check inside each mutations but I think there's a smarter way to do it
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.