[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

Re: [tor-bugs] #10754 [Tor Support]: Implement an invitation based token system into webchat



#10754: Implement an invitation based token system into webchat
-----------------------------+--------------------------
     Reporter:  Sherief      |      Owner:  Sherief
         Type:  task         |     Status:  needs_review
     Priority:  blocker      |  Milestone:
    Component:  Tor Support  |    Version:
   Resolution:               |   Keywords:  SponsorO
Actual Points:               |  Parent ID:  #10755
       Points:               |
-----------------------------+--------------------------

Comment (by lunar):

 Replying to [comment:29 Sherief]:
 > > What if an attacker manage to add data to the DB without going through
 Django's validation process?
 >
 > That's not even possible because:
 > 1) `token_page()` is decorated with `@login_required`.
 > 2) you cannot access create_token() because it's not mentioned in
 urls.py like `token_page()` and `login()`.

 An attacker could gain direct access to the SQL database.

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/10754#comment:30>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online
_______________________________________________
tor-bugs mailing list
tor-bugs@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-bugs