Browse Source
Only the admin user (sudo) is allowed to send notifications to other users. The normal users can only send notifications to themselves. This is to prevent attackers to craft malicious notifications and send them to other users using RPC. Correction based on the idea of @hbrunnpull/1071/head
Guewen Baconnier
6 years ago
committed by
Aitor Bouzas
3 changed files with 18 additions and 2 deletions
Loading…
Reference in new issue