POLIMI-FER-codebenders / tournament_app

Tournament app for Code Defenders made by student team of POLIMI and FER students
GNU Lesser General Public License v3.0
0 stars 0 forks source link

Add global playerID spoofing, add a couple of fixes #23

Closed ricnava00 closed 1 year ago

ricnava00 commented 1 year ago

After adding request-debug=true to the application properties, it's possible to use a playerID parameter in the request to process it as if it came from that player, and authentication gets disabled for all pages