Parse-server: --- REDACTED ---

Created on 30 Nov 2017  路  13Comments  路  Source: parse-community/parse-server

--- REDACTED ---

Most helpful comment

We should put that in place sooner than later. I鈥檒l do it before Monday, with a public pgp key!

All 13 comments

Confirmed, I can reproduce this.

I also tested it on an empty class and a class with objects in it. The bug happens in both cases.

-- REDACTED --

Can you provide the server logs when running with VERBOSE=1?

I believe I found the root cause, and will provide a fix in the next hour

@charleskoehl I'm gonna close this issue now.

I want to take a minute to let you know that issues that may affect security should be privately reported. As mentioned by @milesrichardson everyone now knows the issue, and is able to target the servers.

I've cleaned up the conversation, unfortunately github keeps a tail of events with the changes.

fwiw I can only see that you deleted the comment, can't see the old contents. Maybe you can because you're admin

I'm very sorry for that; I'm sort of a noob in the open source community despite having coded since 1982.

No worry @charleskoehl, mistakes happen. That made me realize we don't have a security 'hotline' / email.

I'm just curious... is there a published confidential disclosure procedure? An email address? Maybe a PGP key?

We should put that in place sooner than later. I鈥檒l do it before Monday, with a public pgp key!

We should also add a notice for responsible disclosures in the the issue/PR template.

Yes, in the issue template, .org domains, and all README鈥檚

Perhaps this could help clean things up more:

https://help.github.com/articles/locking-conversations/

Was this page helpful?
0 / 5 - 0 ratings

Related issues

dpaid picture dpaid  路  3Comments

carjo422 picture carjo422  路  3Comments

ViolentCrumble picture ViolentCrumble  路  3Comments

jaydeep82 picture jaydeep82  路  4Comments

LtrDan picture LtrDan  路  4Comments