You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
As things generally stand currently, users who can access the application can view and modify information about students or goals which have not been assigned to them. On the backend, there is a check in the routers/iep file on the editGoal mutation (pending PR #272), but this otherwise seems largely unaddressed. We should determine what level of security is needed, and whether the approach in editGoal should be repeated or replaced with a more robust solution, such as RLS as previously mentioned by @codetheweb .
The text was updated successfully, but these errors were encountered:
As things generally stand currently, users who can access the application can view and modify information about students or goals which have not been assigned to them. On the backend, there is a check in the
routers/iep
file on the editGoal mutation (pending PR #272), but this otherwise seems largely unaddressed. We should determine what level of security is needed, and whether the approach in editGoal should be repeated or replaced with a more robust solution, such as RLS as previously mentioned by @codetheweb .The text was updated successfully, but these errors were encountered: