Skip to content

--- REDACTED --- #4409

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
charleskoehl opened this issue Nov 30, 2017 · 13 comments
Closed

--- REDACTED --- #4409

charleskoehl opened this issue Nov 30, 2017 · 13 comments

Comments

@charleskoehl
Copy link

charleskoehl commented Nov 30, 2017

--- REDACTED ---

@milesrichardson
Copy link

milesrichardson commented Dec 1, 2017

Confirmed, I can reproduce this.

I also tested it on an empty class and a class with objects in it. The bug happens in both cases.

-- REDACTED --

@flovilmart
Copy link
Contributor

Can you provide the server logs when running with VERBOSE=1?

@flovilmart
Copy link
Contributor

I believe I found the root cause, and will provide a fix in the next hour

@flovilmart
Copy link
Contributor

@charleskoehl I'm gonna close this issue now.

I want to take a minute to let you know that issues that may affect security should be privately reported. As mentioned by @milesrichardson everyone now knows the issue, and is able to target the servers.

@flovilmart flovilmart changed the title CLPs deleted from custom class when starting parse-server v2.7.0 (cannot repro in v2.6.5) --- REDACTED --- Dec 1, 2017
@parse-community parse-community deleted a comment from stevestencil Dec 1, 2017
@flovilmart
Copy link
Contributor

I've cleaned up the conversation, unfortunately github keeps a tail of events with the changes.

@milesrichardson
Copy link

fwiw I can only see that you deleted the comment, can't see the old contents. Maybe you can because you're admin

@charleskoehl
Copy link
Author

I'm very sorry for that; I'm sort of a noob in the open source community despite having coded since 1982.

@flovilmart
Copy link
Contributor

No worry @charleskoehl, mistakes happen. That made me realize we don't have a security 'hotline' / email.

@nbering
Copy link

nbering commented Dec 1, 2017

I'm just curious... is there a published confidential disclosure procedure? An email address? Maybe a PGP key?

@flovilmart
Copy link
Contributor

We should put that in place sooner than later. I’ll do it before Monday, with a public pgp key!

@montymxb
Copy link
Contributor

montymxb commented Dec 2, 2017

We should also add a notice for responsible disclosures in the the issue/PR template.

@flovilmart
Copy link
Contributor

Yes, in the issue template, .org domains, and all README’s

@charleskoehl
Copy link
Author

Perhaps this could help clean things up more:

https://help.github.com/articles/locking-conversations/

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

5 participants