GET RID OF UNSAFE CALLBACKS IN createUser FUNCTION!!! (could have exposed data to unauthorized people)

Ethan Author

… from Stripe

0 Likes
Ethan Author

Ah my keyboard is stuffing up πŸ˜…

0 Likes

o.o

0 Likes
Ethan Author

Lemme try that again

0 Likes

dang.

0 Likes
Ethan Author

But it's all good, I checked the rest of the codebase for other similar issues and didn't find any.

0 Likes
Ethan Author

Luckily it wasn't in production yet. Some of the callbacks included objects

0 Likes
Ethan Author

Luckily it wasn't in production yet. Some of the callbacks included objects from Stripe. Because you can call the function without authorization, someone could have gotten a user's Stripe info based on their email address. Not credit cards, but details about their subscriptions.

0 Likes

glad you patched it up though!

0 Likes

Please sign in to leave a comment.