smswithoutborders / SMSWithoutBorders.com

Here is the interface through which users can manage their accounts and store their credentials
https://smswithoutborders.com
GNU General Public License v3.0
23 stars 8 forks source link

Authenticated but can visit signup and home page #91

Open teyim opened 1 year ago

teyim commented 1 year ago

Describe behavior

I can still access the home screen (the "/" route) even after login, which exposes the login and signup buttons on the navbar, allowing me to visit the signup page while already logged in.

Possible fix

Modify Route guard to prevent user from seeing the home page after being authenticated

PromiseFru commented 1 year ago

Hello @teyim,

Thank you for taking the time to report this issue.

Could you please provide more details regarding the specific vulnerabilities or threats that users may face as a result of this access? Additionally, if possible, could you explain how this could be exploited or cause harm? Any examples of how users may be negatively impacted would also be helpful.

We look forward to hearing back from you and continuing this discussion.