Skip to content

Releases: megahomyak/BAC_light

Trust

11 Nov 22:35
Compare
Choose a tag to compare

Why is it named "trust"? Because in this release I have not made enough security yet! Users do not have roles, so the only way to distinguish employees from clients is to check if the current user has sent a message in the employees' chat or not. This makes a big security problem: if some employee will be hacked or he will have bad motives - strangers can be added to the chat for employees and perform actions on their behalf. We currently have employees we can trust, so... table for all users... maybe... later.