Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security issue #1088

Open
2 tasks done
manuxio opened this issue Jan 7, 2025 · 6 comments
Open
2 tasks done

Security issue #1088

manuxio opened this issue Jan 7, 2025 · 6 comments
Labels
bug Something isn't working

Comments

@manuxio
Copy link

manuxio commented Jan 7, 2025

Checklist

  • I am using the latest version of Alarmo (latest version can be found here)
  • I checked for similar existing requests (both open and closed) before posting.

Alarmo Version

1.10.7

HA Version

2025.1

Bug description

Hello,
how should I report what I think is a security issue?

Steps to reproduce

Cannot reproduce, it's a logical issue

Relevant log output

No response

@manuxio manuxio added the bug Something isn't working label Jan 7, 2025
@nielsfaber
Copy link
Owner

Feel free to share your concerns.

Repository owner deleted a comment from manuxio Jan 7, 2025
@nielsfaber
Copy link
Owner

Thanks for letting me know. I took note of your concerns, I will investigate this later. At this point I’m not sure if this can be improved from within alarmo or is related to HA itself. I will get back to you once I found out.

@manuxio
Copy link
Author

manuxio commented Jan 7, 2025

Thanks for letting me know. I took note of your concerns, I will investigate this later. At this point I’m not sure if this can be improved from within alarmo or is related to HA itself. I will get back to you once I found out.

I am not an HA expert... I am looking at the docs. I think there must be a way to find the user of a post request...
I'll get in touch if I have some info that might help...
Have a good day

@manuxio
Copy link
Author

manuxio commented Jan 21, 2025

Hello?
Any news on that?
I think I might give it a shot... would you eventually consider some PR?

@nielsfaber
Copy link
Owner

No news on this.
I have no time available in the upcoming weeks, due to private priorities.
It would be very helpful if you can investigate this yourself and open a PR for a solution.

@manuxio
Copy link
Author

manuxio commented Jan 21, 2025

No news on this. I have no time available in the upcoming weeks, due to private priorities. It would be very helpful if you can investigate this yourself and open a PR for a solution.

Due to the nature of the issue, I would prefer to use a private PR in order to not publish the details of the issue.
We'll see if time allows...
M.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bug Something isn't working
Projects
None yet
Development

No branches or pull requests

2 participants