[Bug Report] Unauthorized Comment Editing Before Reveal

Hello EasyRetro Team,

I would like to report a security issue I encountered on the platform related to comment editing in a board with hidden comments.

Issue:

Currently, an authenticated user is able to edit another user's comment before it is revealed, exposing its content improperly.

Expected Behavior:

A user should not be able to edit a comment that is not yet visible on the board, ensuring the integrity of the information until it is officially revealed.

Please let me know if you need further details or a step-by-step reproduction of the issue.

I'm happy to assist.

Thank you for your great work!

Best regards,
André Gustavo

Please authenticate to join the conversation.

Upvoters
Status

Rejected

Board

EasyRetro

Date

About 1 year ago

Author

Gustavo Maia

Subscribe to post

Get notified by email when there are changes.