-
-
Notifications
You must be signed in to change notification settings - Fork 795
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[BUG] - Possible to edit cookbook without being logged in #3098
Comments
Hey, thanks for raising this issue. I know that we currently have a few pages that are unsecured and can be accessed when a non logged-in user does access them directly. But the cookbook page is as far as i know not one of them and should reroute you to your last location. I wasn't able to reproduce this on my instance nor on the demo instance. Could you try to reproduce the problem on the demo page, or give more information about how to reproduce it. |
The thing I did: |
Ok, this is verry weird. Thanks for helping me reproduce this! |
Strange that you can directly link there, but only in certain instances. This isn't a security issue because you can't actually edit the cookbook, it just looks like you can |
First Check
What is the issue you are experiencing?
Go to https:///cookbooks without being logged in.
There you can edit cookbooks, again without being logged in.
This is a severe security issue.
Steps to Reproduce
Please provide relevant logs
Mealie Version
Version - nightly
Build - 9bf2e3f
Deployment
Docker (Linux)
Additional Deployment Details
No response
The text was updated successfully, but these errors were encountered: