Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Invoice link that can be set to expire #6408

Open
mzneu opened this issue Aug 5, 2021 · 1 comment
Open

Invoice link that can be set to expire #6408

mzneu opened this issue Aug 5, 2021 · 1 comment

Comments

@mzneu
Copy link

mzneu commented Aug 5, 2021

Hi,
Still self-hosting v4 of Invoiceninja in Docker. Invoiceninja allows the user to email a link to a client allowing the client to view/download/print an invoice after entering a password. I know deleting the invoice will cause this link to expire/malfunction. Is there any way to either set an expiration date for the link (and perhaps a maximum number of allowed views of the invoice), or at least be able to generate a list of active links and disable them individually/manually without actually deleting the invoice?
If there's anyone that is interested and capable of making the above modifications to the source code for me, please let me know the cost.
Thank you.

@kbftech
Copy link

kbftech commented Nov 18, 2022

I'm wondering if someone having access to an old magic link could get into a customer's portal and change his password. It also gives that user the ability to view all the customer's information on file, which is kind of a big deal imo. Am I missing something?

From a test I just did with a fake customer, you can get into the customer's portal and change the password using a magic link. This looks like a bug more than a feature to me. Also kind of a big security threat.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants