Files
once-campfire/app/models/user
Jacopo 3d0a10dbdd Security: Fix user impersonation via custom bot token
If bot_key has no right-hand side (ex: 1-), bot_token will be nil, and the query will match a User record if bot_id matches a valid ID.
Fix it relying on `active_bots` instead.
2025-09-11 12:32:46 +02:00
..
2025-08-21 09:31:59 +01:00
2025-08-21 09:31:59 +01:00
2025-09-02 17:02:41 +02:00
2025-08-21 09:31:59 +01:00