Skip to content

[$250] Inviting users to a group: issue an token and validate accept invitation link #449

Closed
@atelomycterus

Description

@atelomycterus

Any user who knows the accept invitation link format can join groups including private after authorization. It could present a security hole into Vanilla. So before using this functionality with private groups in PROD, need to issue a token/generate invitation code and validate it.

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions