While debugging something else, I scanned a "share coupon" QR with another barcode scanner, and I found that the coupon definition has a field called "showAdmin" in it, which is set to false. It would be simple for someone to create a QR code with showAdmin=true and then what?
While debugging something else, I scanned a "share coupon" QR with another barcode scanner, and I found that the coupon definition has a field called "showAdmin" in it, which is set to false. It would be simple for someone to create a QR code with showAdmin=true and then what?