You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
User Story:
As a host, I don’t want users to be able to arbitrarily execute code on my server to ensure the integrity of the polls and ensure user’s can’t hack me/ cheat.
The text was updated successfully, but these errors were encountered:
florian-str
changed the title
As a host I don’t want users to be able to arbitrarily execute code on my server to ensure the integrity of the polls and ensure user’s can’t hack me/ cheat.
Block remote code execution
May 21, 2024
An old issue (#124) describes the problem in more detail:
With access to perform: and similar messages, one could wreak havoc and circumvent any security measurements put in place. We should guard against this, possibly by only allowing messages to be sent that are implemented directly on the object that's messaged (and not inherited handlers).
User Story:
As a host, I don’t want users to be able to arbitrarily execute code on my server to ensure the integrity of the polls and ensure user’s can’t hack me/ cheat.
The text was updated successfully, but these errors were encountered: