blitz-js / blitz-js/blitzjs.com

Security issues of tutorial

Open
#159 8 comments 0 reactions 0 assignees View on GitHub
good-first-issue hacktoberfest status/ready-to-work-on
Dominant language
MDX
Stars
188
Forks
316
PR merge metrics
No merged PRs in 30d

Description

The tutorial seems to have security issues that anyone can
- create and update any choices through createQuestion
- update choices with any data through updateChoice

I think it should be added a security note or a new section about how to fix the issues.

Demo in browser console:
![image](https://user-images.githubusercontent.com/21266306/92950144-2c60c580-f497-11ea-9cea-344d2004b381.png)

Contributor guide

No contributing guide indexed for this repository

Research direction

Review the tutorial sections covering createQuestion and updateChoice, using the reported browser-console behavior as the starting point. Document the security implications and explain how the tutorial should address unrestricted creation and updates; done means the tutorial includes a clear security note or remediation section.

Written by the indexing model from the issue text.

Assessment

Domain
documentation, security
Issue type
Documentation
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.