sleepy.bike icon indicating copy to clipboard operation
sleepy.bike copied to clipboard

sleepy-bike puts some sensitive information in publicly available solid pod card (images, interests, maybe "about me").

Open dreirund opened this issue 4 months ago • 4 comments

I have set up a sleepy.bike account for me.

After doing so, I found publicly accessible:

  • List of my interests,
  • uploaded profile picture.

Also the "about me" was put into my profile card.

I still can delete the profile picture and the about me from the profile card, and they are still in the hospex/sleepy-bike card. But the interests seem not to be stored in the sleepy-bike card.

To have everything contained within sleepy-bike card and to not accidentally publish information that should be accessible only for sleepy-bike users and to maintain individual manageability of cards, sleepy-bike should only write into it's own card and not change other cards in the Solid pod.

Also, sleepy.bike does not work anymore if I disable public access to my public solid pod card, which I did because sleepy.bike stores sensible information there.

Please fix that.

Also, after changing the descriptive text in the public card, on sleepy.bike there is still my old text (as it should be), but when I click on "edit profile", it shows the new text from the public card, not from the hospex/sleepy-bike card. Something is bogous here, too.

Regards!

dreirund avatar Feb 28 '24 12:02 dreirund