acmpesuecc / Bank-Management-System

MIT License
0 stars 18 forks source link

Unauthorized Access to Account Details and Balance via Account Number or Name #5

Closed Lohithsurya closed 2 weeks ago

Lohithsurya commented 2 weeks ago

Users are able to access sensitive account details, including the balance, by simply knowing the account number or the account holder's name. This poses a privacy risk, as any user with basic information can view the complete account information without proper authentication or authorization.

Expected Behavior: Access to sensitive account details, including balance information, should require proper authentication. Knowing the account number or name should not be sufficient to view full account details.

Shaynazg commented 2 weeks ago

can i please be assigned?

Lohithsurya commented 2 weeks ago

!assign @Shaynazg

Lohithsurya commented 2 weeks ago

@Shaynazg the default time is 30mins show me the progress i will extend the time (show before the time runs out)

Gunika-Goel commented 2 weeks ago

can i be assigned to this please?

bunsamosa-bot[bot] commented 2 weeks ago

Hey @Lohithsurya! The timer for the @Shaynazg to work on the issue has finished, deassign and assign a new contributor or extend the current timer. Contact maintainer leads if inactive @DedLad @polarhive @achyuthcodes30

Lohithsurya commented 2 weeks ago

!deassign

Lohithsurya commented 2 weeks ago

!assign @Gunika-Goel

bunsamosa-bot[bot] commented 2 weeks ago

Hey @Lohithsurya! The timer for the @Gunika-Goel to work on the issue has finished, deassign and assign a new contributor or extend the current timer. Contact maintainer leads if inactive @DedLad @polarhive @achyuthcodes30

Gunika-Goel commented 2 weeks ago

I have sent a pr

bwaklog commented 2 weeks ago

!deassign