Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

【安全建议】希望增加token认证 #134

Closed
4 tasks done
lxflxfcl opened this issue Mar 1, 2024 · 0 comments
Closed
4 tasks done

【安全建议】希望增加token认证 #134

lxflxfcl opened this issue Mar 1, 2024 · 0 comments
Labels
enhancement New feature or request

Comments

@lxflxfcl
Copy link

lxflxfcl commented Mar 1, 2024

例行检查

  • 我已确认目前没有类似 issue
  • 我已确认我已升级到最新版本
  • 我理解并愿意跟进此 issue,协助测试和提供反馈
  • 我理解并认可上述内容,并理解项目维护者精力有限,不遵循规则的 issue 可能会被无视或直接关闭

功能描述
目前推送是只要知道用户名,就可以直接调用并发送推送,容易被恶意用户批量刷垃圾消息,这是我随便从公网找的一个网站,使用用户名root发送成功如下:
image

应用场景
防止恶意用户批量刷消息

@lxflxfcl lxflxfcl added the enhancement New feature or request label Mar 1, 2024
@lxflxfcl lxflxfcl closed this as completed Mar 1, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

1 participant