Discussion:
[sabredav] Organizer can be changed by attendee
codiq
2017-01-11 16:36:14 UTC
Permalink
I was able to change organizer of event by editing attendees copy of it.
When organizer is changed on attendee copy it changes also on organizer
original event.
Is it a bug?
This may be small security problem when attendee can "steal" organizer
status.
--
You received this message because you are subscribed to the Google Groups "SabreDAV Discussion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to sabredav-discuss+***@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/sabredav-discuss/1c103b1d-18f6-4e8b-aca9-b2b5de6a11c0%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
Evert Pot
2017-01-16 00:53:12 UTC
Permalink
It's true this is definitely possible. Most clients enforce the correct
result of these so it never seemed like a big enough problem.

However, feel free to open a bug report for this. Definitely something we
can look into in the future:

https://github.com/fruux/sabre-dav/issues/

Evert
Post by codiq
I was able to change organizer of event by editing attendees copy of it.
When organizer is changed on attendee copy it changes also on organizer
original event.
Is it a bug?
This may be small security problem when attendee can "steal" organizer
status.
--
You received this message because you are subscribed to the Google Groups "SabreDAV Discussion" group.
To unsubscribe from this group and stop receiving emails from it, send an email to sabredav-discuss+***@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/sabredav-discuss/4c7065a9-1501-4881-84d5-3e721a69e14b%40googlegroups.com.
For more options, visit https://groups.google.com/d/optout.
Loading...