
Loading…
|
|
homakov |
Stringify api_key
…
By default there is no api key generated. I just managed to break into api on test installation using `?token[]`, one of my favourite CVEs @radar, please take a look at Mr. Outsider's PR |
e3bbfb2
|
i almost always report it privately. it just feels like a small revenge
That's right. Fuck all these Spree users, nobody gives shit about them. What matters though is small revenge. Way to go, dude.
FWIW: You lived up to the exact description I had in my post. Please stop doing this. You're being a jerk.
| Commit has since been removed from the repository and is no longer available. |
| Commit has since been removed from the repository and is no longer available. |
|
|
homakov |
Stringify api_key
…
Fixes #2492 |
ac2b37c
|
| Commit has since been removed from the repository and is no longer available. |
|
|
homakov |
Stringify api_key
…
Fixes #2492 Conflicts: api/app/controllers/spree/api/v1/base_controller.rb |
0c88742
|
|
|
fmfdias |
Applied changes in commit 6181bb6 from upstream spree.
…
"Stringify api key Fixes #2492" |
1bdc72e
|
No description provided.