Skip to content

Claims plugin does not use unique identifiers #47

@GermaniumSystem

Description

@GermaniumSystem

The claims plugin uses usernames to determine who should or should not be allowed to interact with a protected planet. Since these are not unique, a malicious user can easily log in using a different user's name (or change their name on-the-fly) and gain full access to protected planets.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions