fix: add server-side role check on sync-elements and sync-state socket events - #131
Open
HunarBhatia wants to merge 1 commit into
Open
fix: add server-side role check on sync-elements and sync-state socket events#131HunarBhatia wants to merge 1 commit into
HunarBhatia wants to merge 1 commit into
Conversation
…t events Fixes KENZY004#81 - sync-elements: verify socket.userId matches board.createdBy before syncing - sync-state: verify socket.userId matches board.createdBy before syncing - Both events now return unauthorized error to client if check fails - Prevents students from overwriting entire board state via browser console
|
Someone is attempting to deploy a commit to the MINHA's projects Team on Vercel. A member of the Team first needs to authorize it. |
Contributor
Author
|
@KENZY004 PR submitted! Would it be possible to add relevant labels like |
Owner
|
Looks great overall! Just one small issue: Could you update the condition to include those cases? Once that's done, I'll merge it right away. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #81
Problem
The
sync-elementsandsync-statesocket events had no server-side authorization check. Any authenticated student could emit these events directly from the browser console and completely overwrite the entire board state — both in the live session and the database — bypassing the existingallowedStudentsandallowStudentEditingpermission system entirely.Fix
Added a board ownership check to both events using
socket.userIdcompared againstboard.createdBy:Events Fixed
sync-elements— only board owner can sync full element arraysync-state— only board owner can sync full board stateFile Changed
server/index.js