Bug: Self hosted invite codes should only be generated by admins #1606
Labels
💻 Self Hosted only
Issues pertaining to self-hosted versions of Maybe
2️⃣ Medium Priority
Community contributions accepted, Maybe team only works on if there are no high priority items open
Hello 👋
Describe the bug
I found a security issue. All users can create invite codes.
To Reproduce
Steps to reproduce the behavior:
Require invite code for new sign ups
Settings > Self Hosted
Expected behavior
I think only "admin" users could generate codes.
What version of Maybe are you using?
Self Hosted, v0.2.0
What operating system and browser are you using?
The problem is on all OS and browsers
An idea to fix this problem would be to set an "admin email" in env vars. Only the user logged in with this email could do some actions like generate invite code.
If this solution sounds good to you, I can implement it.
The text was updated successfully, but these errors were encountered: