digidem / mapeo-core-next

The upcoming version of Mapeo Core
MIT License
7 stars 1 forks source link

chore: invites should use special invite ID, not project public key #571

Closed EvanHahn closed 1 month ago

EvanHahn commented 3 months ago

A sophisticated bad actor who knows a project's public ID could spam invites to determine whether someone was in a project.

Now, they need the harder-to-get "project invite ID", which is a separate generated value.

Closes #559.