Logo
Explore Help
Sign In
LotusGuild/tinker_tickets
Watch 4
Star 0
Fork 0
Code Issues 46 Pull Requests Actions Packages Projects Releases Wiki Activity
Labels Milestones New Issue
17 Open 5 Closed
Label
Use alt + click/enter to exclude labels
All labels No label
api

bug

concurrency

config

data-integrity

dead-code

documentation

duplicate

enhancement

help wanted

invalid

needs-decision

notifications

performance

priority/docs

priority/high

priority/low

priority/medium

question

rate-limiting

reliability

security

ux

wontfix

workflow

Milestone
All milestones No milestones
Project
All projects No project
Author
All users
Assignee
Assigned to nobody Assigned to anybody
cole (Cole Keller) jared (Jared Vititoe) nathan (Nathan Vititoe)
Sort
Newest Oldest Most recently updated Least recently updated Most commented Least commented Nearest due date Farthest due date
17 Open 5 Closed
Label
Clear labels
api
bug
concurrency
config
data-integrity
dead-code
documentation
duplicate
enhancement
help wanted
invalid
needs-decision
notifications
performance
priority/docs
priority/high
priority/low
priority/medium
question
rate-limiting
reliability
security
ux
wontfix
workflow
Milestone
No milestone
Projects
Clear projects
Assignee
Clear assignees
cole
jared
nathan
DB connection failure leaks raw mysqli error text to any unauthenticated visitor priority/mediumsecurity
#104
opened 2026-09-01 00:21:12 -04:00 by jared
LDAP bind credentials transmitted in plaintext (no TLS) priority/mediumsecurity
#95
opened 2026-09-01 00:13:37 -04:00 by jared
TRUSTED_PROXIES ships empty/disabled by default — full admin-impersonation risk if not explicitly configured configpriority/highsecurity
#94
opened 2026-09-01 00:13:36 -04:00 by jared
12 of ~16 hand-rolled CSRF checks omit csrf_token from their rejection response, breaking client-side resync app-wide priority/highsecurity
#85
opened 2026-09-01 00:08:16 -04:00 by jared
Bearer API endpoints are rate-limited purely by shared IP, not by API key — one key can starve another priority/mediumrate-limitingsecurity
#81
opened 2026-09-01 00:07:14 -04:00 by jared
Watchers are never pruned when a ticket's visibility is tightened notificationspriority/mediumsecurity
#73
opened 2026-09-01 00:07:10 -04:00 by jared
sendAssignmentNotification() has the same missing-visibility-check gap as #46 notificationspriority/mediumsecurity
#72
opened 2026-09-01 00:07:10 -04:00 by jared
notifyWatchers() only half-redacts for non-public tickets — title and shared notify-list still leak notificationspriority/mediumsecurity
#71
opened 2026-09-01 00:07:09 -04:00 by jared
Bearer read-scope API keys bypass ticket visibility entirely — confirm this is an intentional, documented decision needs-decisionpriority/highsecurity
#70
opened 2026-09-01 00:07:09 -04:00 by jared
@mention notifications leak confidential/internal ticket content to users with no access — worse than #46 notificationspriority/highsecurity
#69
opened 2026-09-01 00:07:08 -04:00 by jared
hwmonDaemon 'reopen closed duplicate' path bypasses Workflow Designer validation entirely via raw SQL priority/highsecurityworkflow
#68
opened 2026-09-01 00:07:08 -04:00 by jared
Stale sessions never re-sync privileges from Authelia (revoked admin keeps access up to 5h) priority/highsecurity
#56
opened 2026-08-31 21:40:09 -04:00 by jared
Custom field values have no server-side validation against field_type or select options priority/mediumsecurity
#50
opened 2026-08-31 21:36:18 -04:00 by jared
api/notifications.php: in-app notifications don't re-check current ticket visibility notificationspriority/mediumsecurity
#48
opened 2026-08-31 21:36:17 -04:00 by jared
Confidential/internal ticket titles leak to Matrix on create/status-change (NotificationHelper missing visibility check) notificationspriority/highsecurity
#46
opened 2026-08-31 21:36:16 -04:00 by jared
base.js: unused lt.markdown module has no URL-protocol allowlist on links — latent stored-XSS trap dead-codepriority/lowsecurity
#43
opened 2026-08-31 21:29:47 -04:00 by jared
13 of 33 API endpoints never disable display_errors — potential stack-trace leak priority/mediumsecurity
#39
opened 2026-08-31 21:29:45 -04:00 by jared
Powered by Gitea Version: 1.27.1 Page: 16ms Template: 5ms
Auto
English
Bahasa Indonesia Deutsch English Español Français Gaeilge Italiano Latviešu Magyar nyelv Nederlands Polski Português de Portugal Português do Brasil Suomi Svenska Türkçe Čeština Ελληνικά Български Русский Українська فارسی മലയാളം 日本語 简体中文 繁體中文(台灣) 繁體中文(香港) 한국어
Licenses API