Closed WYHNUS closed 7 years ago
User id should be recovered from token instead accepting what the user sends. (currently any user can unattend an event on behalf of another user)
Creator able to edit event
Creator able to delete event
@ZhangHanming @WYHNUS it's done right?
Done.
User id should be recovered from token instead accepting what the user sends. (currently any user can unattend an event on behalf of another user)
Creator able to edit event
Creator able to delete event