Please upgrade here. These earlier versions are no longer being updated and have security issues.
HackerOne users: Testing against this community violates our program's Terms of Service and will result in your bounty being denied.
Social Connect allows users to circumvent invite system
Could not find a thread regarding this, so please let me know if this has yet to be noted:
If you have invites turned on, users can access the system without an invite code by using one of the other sign-in options (OpenID/Facebook/Twitter/etc.)
I have turned off Social Connections for now.
I'll create a GitHub issue if nobody has noticed this yet.
If you have invites turned on, users can access the system without an invite code by using one of the other sign-in options (OpenID/Facebook/Twitter/etc.)
I have turned off Social Connections for now.
I'll create a GitHub issue if nobody has noticed this yet.
0
Comments
/cd
Once you've been invited and signed up, you can activate it, and use your single sign-on authentication without worrying about the forum password. It's a matter of convenience.
If a user attempts to use Social Connect to access a private system, one would assume they'd hit the "you need an invite code" wall.
Thanks for getting back on this.