Avatar

cantevencode

cantevencode@lemmy.world
Joined
0 posts • 15 comments
Direct message

Good point. I suppose the only way to fix that particular issue to disallow cookie authentications from a new location

permalink
report
parent
reply

Prior to the JWT secret being rotated, yes, they could have authenticated as you. The tokens are now all invalid and useless

permalink
report
parent
reply

Does an admin account have any permissions to view email addresses or data of registered users?

Did MichelleG not have 2FA enabled?

Now that this has happened, it’s be worth pushing this issue through as high priority. If HttpOnly was enabled, then an admin takeover would not have been possible.

https://github.com/LemmyNet/lemmy-ui/issues/1252

permalink
report
reply

Petition to change the lemmy.world logo to Lenny

permalink
report
parent
reply