Skip to content

[IDOR] sécurisation des urls de fusion de membres [GEN-2400]#5420

Merged
vincentporte merged 1 commit into
masterfrom
vp/idor_merge_users
Jan 21, 2025
Merged

[IDOR] sécurisation des urls de fusion de membres [GEN-2400]#5420
vincentporte merged 1 commit into
masterfrom
vp/idor_merge_users

Conversation

@vincentporte

@vincentporte vincentporte commented Jan 20, 2025

Copy link
Copy Markdown

🤔 Pourquoi ?

la fusion de membres est actionnable à partir des id incrémental des users

Catégories changelog

Admin

🍰 Comment ?

remplacer les id par les public_id

🚨 À vérifier

  • Mettre à jour le CHANGELOG_breaking_changes.md ? > Non

ref notion

@vincentporte vincentporte self-assigned this Jan 20, 2025

@francoisfreitag francoisfreitag left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comme la vue est réservée aux superutilisateurs (qui ont accès à l’admin django), il n’y a pas d’IDOR. Mais on peut toujours préférer l’utilisation du public id 👍

@vincentporte vincentporte added this pull request to the merge queue Jan 21, 2025
Merged via the queue into master with commit 6e22ded Jan 21, 2025
@vincentporte vincentporte deleted the vp/idor_merge_users branch January 21, 2025 09:54
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants