bountysource / bountysource/core
Security needs to be tightened
Open
- Dominant language
- Ruby
- Stars
- 643
- Forks
- 199
- PR merge metrics
- No merged PRs in 30d
Description
It should be impossible to create multiple account in a short time from the same IP.
It should be impossible to use the same username or visually similar username as existing users.
It should be impossible to claim a bounty less than 48h from the account creation.
A bounty of us is getting hammered by morons, creating claims with fake accounts impersonating other users: this should not even be possible by bounty source.
Please do the needful to prevent these behaviours.
Contributor guide
Assessment
This issue has not been assessed yet.