mbreslein-thd

Results 7 comments of mbreslein-thd

This line seems to be the culprit: https://github.com/RocketChat/Rocket.Chat/blob/develop/apps/meteor/app/api/server/v1/oauthapps.ts#L30 It was introduced in this commit: https://github.com/RocketChat/Rocket.Chat/commit/5bb039037015d7d4cd3dcd255ac89e63dbe5c84c This should fix it: https://github.com/RocketChat/Rocket.Chat/pull/31771

> is it possible to add some tests validating that the login with third party apps is working even without the 'manage-oauth-apps' permission? It would probably be a good idea...

> Just pushed the new permission to the branch, please update the tests :P Thank you. Done: https://github.com/RocketChat/Rocket.Chat/pull/31771/commits/ffd96c382f3aacb3f9b8b5ff8da35b8c976a8343

> People, we are further analyzing this and related PR as there is a security concern. Will get back with more details ASAP. I'd like to point out that the...

This issue still persists 15 Months later. Any help with this would be appreciated.