Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Users should not have access to view all machine IDs on web UI #11

Open
Snuupy opened this issue Sep 7, 2024 · 0 comments
Open

Users should not have access to view all machine IDs on web UI #11

Snuupy opened this issue Sep 7, 2024 · 0 comments
Labels
enhancement New feature or request good first issue Good for newcomers

Comments

@Snuupy
Copy link

Snuupy commented Sep 7, 2024

Describe the bug

Currently users can view all machine IDs even if they should not have access to them. Although machines are protected with passwords, this still exposes metadata that should not be exposed, leaking information (though hopefully your users are not your adversaries!)

This also applies to the groups tab in the rustdesk app.

Describe the environment

Not relevant, but docker compose, latest

How to Reproduce the bug
Steps to reproduce the behavior:

  1. create a normal non-admin user
  2. browse devices page, see all devices listed

Expected behavior

only devices for that individual user should be listed if they are not an admin

Additional context

N/A

Notes

  • Please write in english only. If you provide some images in different languages, you're required to write a translation in english.
  • In any case, NEVER put here the content if your id_ed25519 file
@Snuupy Snuupy added the bug Something isn't working label Sep 7, 2024
@eltorio eltorio added the good first issue Good for newcomers label Sep 7, 2024
@aeltorio aeltorio transferred this issue from sctg-development/sctgdesk-server Sep 7, 2024
@aeltorio aeltorio added enhancement New feature or request and removed bug Something isn't working labels Sep 7, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request good first issue Good for newcomers
Projects
None yet
Development

No branches or pull requests

3 participants