alcalcides / adretiro-api

This api is to support the app adretiro, that is like a sticker album. When an user collects all stickers, he can claim a reward.
GNU General Public License v2.0
0 stars 0 forks source link

Security: don't allow an user access another user data #3

Open alcalcides opened 3 years ago

alcalcides commented 3 years ago

The resources below is for managers and the same contributor. A contributor cannot use his authentication to fetch like another contributor

/people/:id /contributions/:id