nodeSolidServer / nodeSolidServer/node-solid-server
Don't rely on existence of /profile/card to block sign-up.
@jaxoncreed is already working on this.
Since Dec 10, 2019.
- Dominant language
- JavaScript
- Stars
- 1.8k
- Forks
- 308
- PR merge metrics
- No merged PRs in 30d
Description
In single-user mode, you can register once.
If you try to register a second time, https://github.com/solid/node-solid-server/blob/master/lib/models/account-manager.js#L111 will notice that ./data/profile/card$.ttl already exists, and respond with a 400.
However, if you manually delete that file, then that means that if someone goes to the Register page, they can take over control of your pod.
For multi-user mode, this would presumably work too, but then you need to "guess" the username for which the profile doc is missing, so it's less likely to occur.
We could change the check for user existence, for instance, (also) check if an oidc user exists, or if a data folder exists at all.
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.