stuysu / epsilon

all in one service for stuyvesant high school.
8 stars 0 forks source link

User's can upload whatever creator_id they want #10

Closed randysim closed 2 weeks ago

randysim commented 2 months ago

User's trying to bypass security are able to create organizations and assign any user as the creator of it (there is a creator_id field on organizations). We should create a supabase edge function that lets the server handle this logic with authentication.