metarhia / metarhia/Example

Potentially dangerous code

Open
#210 2 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
JavaScript
Stars
211
Forks
82
PR merge metrics
No merged PRs in 30d

Description

https://github.com/metarhia/Example/blob/8a505455d984b6f34d6397bafcf0aeed0dec39e2/application/api/auth.2/signin.js#L7

The plain password must not be transferred to the 3rd-party code.
This code must use node-embedded functions to get hash and compare it with the stored one.
By the way the password must be salted.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start at application/api/auth.2/signin.js line 7 and trace how the password reaches the third-party code. The issue is done when password handling uses Node.js-embedded functions, compares a salted hash with the stored value, and does not transfer the plain password; no test file is named.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript, node.js
Domain
authentication, backend, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.