ajsharma / adventures

Strange But Wonderful - Adventures
www.adventureshq.com
1 stars 0 forks source link

Token should be required to heart an adventure #16

Open ajsharma opened 11 years ago

ajsharma commented 11 years ago

There's no security check for the heart controller endpoint, so anyone with the adventure id could send a POST and get access.