Logo
Explore Help
Sign In
LotusGuild/tinker_tickets
Watch 4
Star 0
Fork 0
Code Issues 46 Pull Requests Actions Packages Projects Releases Wiki Activity
Labels Milestones New Issue
10 Open 8 Closed
Label
Use alt + click/enter to exclude labels
All labels No label
api

bug

concurrency

config

data-integrity

dead-code

documentation

duplicate

enhancement

help wanted

invalid

needs-decision

notifications

performance

priority/docs

priority/high

priority/low

priority/medium

question

rate-limiting

reliability

security

ux

wontfix

workflow

Milestone
All milestones No milestones
Project
All projects No project
Author
All users
Assignee
Assigned to nobody Assigned to anybody
cole (Cole Keller) jared (Jared Vititoe) nathan (Nathan Vititoe)
Sort
Newest Oldest Most recently updated Least recently updated Most commented Least commented Nearest due date Farthest due date
10 Open 8 Closed
Label
Clear labels
api
bug
concurrency
config
data-integrity
dead-code
documentation
duplicate
enhancement
help wanted
invalid
needs-decision
notifications
performance
priority/docs
priority/high
priority/low
priority/medium
question
rate-limiting
reliability
security
ux
wontfix
workflow
Milestone
No milestone
Projects
Clear projects
Assignee
Clear assignees
cole
jared
nathan
index.php and create_ticket_api.php use their own raw mysqli connections instead of Database::getConnection() — missing charset/timezone sync on most page traffic data-integritypriority/high
#103
opened 2026-09-01 00:21:11 -04:00 by jared
TRUSTED_PROXIES ships empty/disabled by default — full admin-impersonation risk if not explicitly configured configpriority/highsecurity
#94
opened 2026-09-01 00:13:36 -04:00 by jared
12 of ~16 hand-rolled CSRF checks omit csrf_token from their rejection response, breaking client-side resync app-wide priority/highsecurity
#85
opened 2026-09-01 00:08:16 -04:00 by jared
Bearer read-scope API keys bypass ticket visibility entirely — confirm this is an intentional, documented decision needs-decisionpriority/highsecurity
#70
opened 2026-09-01 00:07:09 -04:00 by jared
@mention notifications leak confidential/internal ticket content to users with no access — worse than #46 notificationspriority/highsecurity
#69
opened 2026-09-01 00:07:08 -04:00 by jared
hwmonDaemon 'reopen closed duplicate' path bypasses Workflow Designer validation entirely via raw SQL priority/highsecurityworkflow
#68
opened 2026-09-01 00:07:08 -04:00 by jared
Bulk operations never fire Matrix/watcher notifications for status changes notificationspriority/high
#67
opened 2026-09-01 00:07:07 -04:00 by jared
Stale sessions never re-sync privileges from Authelia (revoked admin keeps access up to 5h) priority/highsecurity
#56
opened 2026-08-31 21:40:09 -04:00 by jared
Custom Fields feature is entirely disconnected from ticket creation/editing/viewing priority/highux
#47
opened 2026-08-31 21:36:16 -04:00 by jared
Confidential/internal ticket titles leak to Matrix on create/status-change (NotificationHelper missing visibility check) notificationspriority/highsecurity
#46
opened 2026-08-31 21:36:16 -04:00 by jared
Powered by Gitea Version: 1.27.1 Page: 13ms Template: 4ms
Auto
English
Bahasa Indonesia Deutsch English Español Français Gaeilge Italiano Latviešu Magyar nyelv Nederlands Polski Português de Portugal Português do Brasil Suomi Svenska Türkçe Čeština Ελληνικά Български Русский Українська فارسی മലയാളം 日本語 简体中文 繁體中文(台灣) 繁體中文(香港) 한국어
Licenses API