abcnews / editorslab-2017

Our work at Walkleys/GEN Editors Lab Sydney event in 2017
https://initiatecontact.com
MIT License
7 stars 1 forks source link

Randomise user IDs #10

Open drzax opened 7 years ago

drzax commented 7 years ago

As suggested by a user:

I've come across a possibly unintended feature of your service.

https://initiatecontact.com/submit?user=1

This is your contact url. If someone simply increments this number you can see everyone who has signed up (some duplicates).

Not sure if you think this is a feature that should exist.

Why is this an issue? If someone 'signed up' to see if it would work and decided not to use it - they're here for as long as their keybase account exists along with a link to their email address.

They could block the domain, but that's not a very friendly solution.

Consider adding to the roadmap some type of more random user generation number/method (if you haven't already) - or some other authenticated way to remove your account.