Skip to content

Memberships security issue? #67

@wnggf

Description

@wnggf

Hello, i have set up category memberships, so only certain users can see a product category. but if your signed in as a user without that membership (you cant see the category listed on the main page, but), you can still access that category by just changing the number in the address bar - cart.php?target=category&category_id=3. by changing the id=3 to id=2 you can access it with the wrong account. am i doing something wrong?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions