Api: Pending clan member endpoint does not honour authorisation

Created on 31 Aug 2019  Â·  2Comments  Â·  Source: Bungie-net/api

The /GroupV2/{$id}/Members/Pending/ endpoint correctly requires authentication, however, once a user is authenticated, they can see _any_ clan's pending members — regardless of whether they're authorised to do so. (I assume that since this is not the way BungieNet works, that this is not the intended behaviour.)

bug investigation

Most helpful comment

Ah, thank you for the heads up! I appreciate it!

All 2 comments

Can be reproduced here http://braytech.org/clan/admin

Ah, thank you for the heads up! I appreciate it!

Was this page helpful?
0 / 5 - 0 ratings