Skip to content

Security BUG in the "How To Setup Logout Flow & App Deployment : RLS Series" videos #52

@LeonidShamis

Description

@LeonidShamis

Hi,

You can see the issue at 5:09:

When the user logs in with "vihar@appsmith.com", you can see the records owned by "confidence@appsmith.com" briefly displayed, then removed and replaced with the records belonging to "vihar@appsmith.com".

The same occurs when users logs out of the session for "vihar@appsmith.com" at 5:25 and logs in with "confidence@appsmith.com" - records belonging to "vihar@appsmith.com" are shown for a seconds, then removed and replaced by the records owned by "confidence@appsmith.com".

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions