Skip to content

API has no permission restrictions on private lobbies #344

@Mubelotix

Description

@Mubelotix

Any user has as much power as the creator of the private lobby as long as they have the code.

I was able to launch a game even though the button did not display to me.

Image

I was also able to send successful requests modifying parameters of the game before it starts, but it appears they get overridden by the legitimate session anyway.

I can craft a PR to fix this if that is convenient for you

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    Projects

    Status

    Pre-Development

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions