Skip to content

Treat widget submissions as anonymous - #370

Merged
Cannonb4ll merged 1 commit into
ploi:mainfrom
bjarn:codex/fix-widget-email-identity
Oct 5, 2026
Merged

Cannonb4ll merged 1 commit into
ploi:mainfrom
bjarn:codex/fix-widget-email-identity

Conversation

@bjarn

@bjarn bjarn commented Oct 2, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Stop using an unsigned widget email address as account identity.
  • Create widget feedback without a user assignment or automatic vote.
  • Keep the current request fields for compatibility.
  • Add regression tests for account assignment, votes, and activity attribution.

Security impact

A caller could submit an existing account email and create feedback, votes, and activity under that account.

Tests

  • php artisan test --compact tests/Feature/Widget/WidgetTest.php

@Cannonb4ll
Cannonb4ll merged commit cee5b50 into ploi:main Oct 5, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants