Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

User Can Delete Events Created by Others #268

Closed
palisadoes opened this issue May 25, 2021 · 1 comment
Closed

User Can Delete Events Created by Others #268

palisadoes opened this issue May 25, 2021 · 1 comment
Labels
bug Something isn't working unapproved Unapproved for Pull Request

Comments

@palisadoes
Copy link
Contributor

Describe the bug

  1. It was discovered in [Security Bug] User can delete any event (Front-end) talawa#832 that mobile app users can delete the events created by others.
  2. This must not be possible in the API

To Reproduce

Steps to reproduce the behavior:

  1. See [Security Bug] User can delete any event (Front-end) talawa#832

Expected behavior

  1. An action prohibited response error should be generated

Actual behavior

See PalisadoesFoundation/talawa#832

Screenshots

See PalisadoesFoundation/talawa#832

Additional details

N/A

@github-actions github-actions bot added bug Something isn't working unapproved Unapproved for Pull Request labels May 25, 2021
@palisadoes
Copy link
Contributor Author

Duplicate Issue #261

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working unapproved Unapproved for Pull Request
Projects
None yet
Development

No branches or pull requests

1 participant