vandalizing other people's cards should be prevented

The project looks very nice, but it’s possible to vandalize other users’ cards/profiles:

Let's say user A creates a card with custom design id afB0FP_V and embeds the created card in their GitHub profile. Then user B can see in user A's profile which design id the card uses and make a request to the githubcard.com API (PUT

https://githubcard.com/api/v1/designs/afB0FP_V) to update this design and completely change its contents. This overrides user A's design and allows user B to vandalize user A's GitHub profile.

Please authenticate to join the conversation.

Upvoters
Status

Completed

Board
💡

Feature Request

Tags

High Priority

Date

6 months ago

Author

martin

Subscribe to post

Get notified by email when there are changes.