issues Search Results · language:Dune language:Python language:TypeScript language:JavaScript language:TypeScript
Filter by
56.5M results
复现步骤
1. 以普通用户登录 (qr_1780942490)
2. PUT /api/v1/settings/users/{自己的uuid} { roles :[ admin ]}
3. 返回 code=0, User updated
实际行为
用户可自行修改自己的角色为 admin,无需任何审批。
安全影响
任何已认证用户可将自身提升为管理员。
Acceptance Criteria ...
mod:api
P0
security
Priority / Lift
P1 · Lift: S
Problem
When a captain opens a draft via their one-time token link, the token is exchanged client-side, but the exchange has a
bare .catch() that swallows all errors:
src/components/draft/DraftBoardClient.tsx:32-50 ...
复现步骤
1. 以普通用户登录 (qr_1780942490, is_admin=false)
2. POST /api/v1/settings/users { username : r49_admin_takeover , password : 1 , display_name : hacker , email :
evil@test.com , roles :[ admin ]} ...
mod:api
P0
security
Documentation Type
Missing documentation (feature not documented)
Documentation Location
https://code.claude.com/docs/en/workflows
Section/Topic
The Watch the run section and the description of the ...
Using Up arrow no longer displays the input history in new sessions
!-- VSCE_TRIAGE_AGENT:{ run :27177416123, t : 2026-06-09T01:12:17.090Z } --
Priority / Lift
P1 (before wide public launch) · Lift: XS (copy/title only)
Problem
God draft is internal naming for the in-game god pick/ban phase, but it leaks into user-facing UI:
- Browser tab ...
기능 설명
경로 작성 사이드 탭 구현
필요한 이유
경로 작성시에 들어가야 할 세부 사항들을 구현
제안하는 해결 방법
No response
대안
No response
추가 정보
No response
enhancement
feature
Objetivo\nCriar um checklist unico de preflight para os agentes do projeto, reduzindo erros operacionais repetidos antes de qualquer acao de escrita, revisao ou publicacao.\n\n## Escopo\n- confirmar fonte ...
area: architecture
priority: p2
ready-for-dev
type: tech-task

Learn how you can use GitHub Issues to plan and track your work.
Save views for sprints, backlogs, teams, or releases. Rank, sort, and filter issues to suit the occasion. The possibilities are endless.Learn more about GitHub IssuesProTip! Restrict your search to the title by using the in:title qualifier.