The project looks very nice, but it’s possible to vandalize other users’ cards/profiles:
Let's say user A creates a card with custom design id afB0FP_V and embeds the created card in their GitHub profile. Then user B can see in user A's profile which design id the card uses and make a request to the githubcard.com API (PUT
https://githubcard.com/api/v1/designs/afB0FP_V) to update this design and completely change its contents. This overrides user A's design and allows user B to vandalize user A's GitHub profile.
Please authenticate to join the conversation.
Completed
Feature Request
High Priority
6 months ago

martin
Get notified by email when there are changes.
Completed
Feature Request
High Priority
6 months ago

martin
Get notified by email when there are changes.