Skip to content

fix: hide bounty admin actions and stop subdomain handle oracle#299

Open
ElizaBackrooms wants to merge 1 commit into
algora-io:mainfrom
ElizaBackrooms:fix/bounty-ui-auth-and-subdomain-oracle
Open

fix: hide bounty admin actions and stop subdomain handle oracle#299
ElizaBackrooms wants to merge 1 commit into
algora-io:mainfrom
ElizaBackrooms:fix/bounty-ui-auth-and-subdomain-oracle

Conversation

@ElizaBackrooms
Copy link
Copy Markdown

Summary

Test plan

  • Log in as a non-admin org member and confirm bounty admin buttons are hidden on /{org}/bounties.
  • Log in as org admin/mod and confirm buttons still appear and work.
  • Visit {valid-handle}.algora.io and confirm redirect still works without firing a critical alert.
  • Visit {invalid-handle}.algora.io and confirm behavior is unchanged for unknown handles.

Closes #238
Closes #201

Only show Edit Amount and Delete controls to org admins and mods on the
bounties table. Remove critical alerts when a subdomain matches a user
handle so attackers cannot enumerate valid profiles via side channels.

Fixes algora-io#238
Fixes algora-io#201

Co-authored-by: Cursor <cursoragent@cursor.com>
@CLAassistant
Copy link
Copy Markdown

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.


Francisco Lopez seems not to be a GitHub user. You need a GitHub account to be able to sign the CLA. If you have already a GitHub account, please add the email address used for this commit to your account.
You have signed the CLA already but the status is still pending? Let us recheck it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants