teambox
teambox copied to clipboard
Hide people's data exports
Without this patch, you can see other people's data exports, e.g : https://teambox.com/datas/2336
May I add that this is a live security hole ?
Anybody can see the list of data exports from other people's account. The "space150 scrum" project I'm referring was probably made by @space150 and by poking into other export ids you can get to a lot of exports : https://teambox.com/datas/1045 https://teambox.com/datas/1045 https://teambox.com/datas/1985 https://teambox.com/datas/2009 …
Cough.
Yearly cough.