cloudfoundry-incubator / admin-ui

Need new main contributor - An application for viewing Cloud Foundry metrics and operations data.
Apache License 2.0
71 stars 44 forks source link

I can become Dark Lord using admin-ui #126

Closed allomov closed 9 years ago

allomov commented 9 years ago

I don't know if it is bug or feature, but username that is displayed on the page is passed to admin-ui in url parameter. It allows me to become Dark Lord by passing ?user=DarkLord in url.

demo

What do you think about it ?

Guys are concerned about this issue: dark-lords

rboykin commented 9 years ago

The value is only used as a mechanism to display the current logged-in user and displays as you see. It is not used for anything else.

allomov commented 9 years ago

That's okey. I was little bit surprised to such solution. Do you plan any changes for this behaviour?

rboykin commented 9 years ago

I do not expect any change to this behavior since the behavior is innocuous.