jaktestowac / gad-gui-api-demo

GAD🦎 - Application for learning testing GUI and API
https://jaktestowac.pl/about-gad
GNU General Public License v3.0
14 stars 10 forks source link

[Bug] Lack of security #37

Closed marcinbubolc closed 4 months ago

marcinbubolc commented 5 months ago

Describe the bug I can enter the page which should be available only for logged in users

To Reproduce Steps to reproduce the behavior: 1.Logout from GAD

  1. Type in browser direct url to specific page - for example http://localhost:3001/users.html , http://localhost:3001/stats/stats.html
  2. Check list of users

Expected behavior Website should display a notification that access to the page is only available to a limited group of users

Screenshots image

Desktop (please complete the following information):