ProjectCopilot / mailroom

Copilot's air traffic controller.
1 stars 0 forks source link

Open API Endpoint — Firebase Security Issue /api/getRequests/:n #92

Closed gmittal closed 7 years ago

gmittal commented 7 years ago

Currently anyone can access our Firebase by simply knowing our API endpoint. Instead of returning entire Firebase JSON content, just return an array of case IDs.