Skip to content

GraphQL WebSockets API is completely unsecured #66

Open
@petschekr

Description

@petschekr

Anyone can open a connection to wss://checkin.hack.gt/graphql and send the correct commands to set up a GraphQL subscription to any checkin events -- even without authenticating.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions