Add team ownership check in /injury set-new
#18
Labels
No Label
ai-changes-requested
ai-pr-opened
ai-reviewed
ai-reviewing
ai-working
in-next-release
status/in-progress
status/pr-open
No Milestone
No project
No Assignees
1 Participants
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: cal/major-domo-v2#18
Loading…
Reference in New Issue
Block a user
No description provided.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Description
commands/injuries/management.py:418— Theinjury_set_newcommand explicitly skips verifying that the invoking user actually owns the team the player is on. The comment reads:# TODO: Add team ownership verification. Any league player with theSeason 13 Playersrole can currently set an injury on any player on any team without being blocked.File Locations
commands/injuries/management.py:418Labels
security, bug, todo
Priority
high