kaka-ruto / carpitan

Power to the People
MIT License
79 stars 32 forks source link

Feature Suggestion Section #15

Open karvel-code opened 2 weeks ago

karvel-code commented 2 weeks ago
kaka-ruto commented 2 weeks ago

Good suggestion. Something like this that we have for Autohaven? https://autohaven.canny.io/requests

It ticks all the checkboxes above except the last one.

The having to login feature is a security feature. Without requiring login, it can be badly misused by eg bots who can create thousands of records automatically since they do not have to create accounts

Let me know if you like the one we have on Autohaven and I can create the same.

GithinjiV commented 3 days ago

Not quite a feature, but a security issue. I have been looking at the routes drawn using the madmin gem and see that there is the madmin users link that shows the user details. I'm thinking the user details should be private(mostly user email).