bountysource / bountysource/core

Security needs to be tightened

Open
#1,377 0 comments 2 reactions 0 assignees View on GitHub
Dominant language
Ruby
Stars
643
Forks
199
PR merge metrics
No merged PRs in 30d

Description

It should be impossible to create multiple account in a short time from the same IP.
It should be impossible to use the same username or visually similar username as existing users.
It should be impossible to claim a bounty less than 48h from the account creation.

A bounty of us is getting hammered by morons, creating claims with fake accounts impersonating other users: this should not even be possible by bounty source.

Please do the needful to prevent these behaviours.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.