aswell with view state from database
anonymous users should not modify anything on database at al, just access
貢獻者指南
技術棧
javascript
領域
securityauthenticationbackend
議題類型
security
難度面向新貢獻者的預計實作難度,1 表示很小改動,5 表示專家級工作。
3
預計時間有經驗貢獻者完成調查、實作、測試並準備 pull request 的粗略時間範圍。
half day
活動狀態議題目前的可參與程度:新鮮、活躍、陳舊、阻塞或等待維護者輸入。
stale
清晰度議題是否清楚說明預期改動、驗收標準和下一步。
unclear
前置要求
understanding of the application's authentication flowknowledge of database queries for user profiles and view state
新手友善度1-100 的估計分數,表示該議題對首次貢獻者的友善程度。
30
研究方向
Examine the codebase to understand how anonymous users are currently handled. Look for authentication middleware (likely in a Node.js/Express setup) that controls access to routes related to profiles and view state. Check the database schema for tables storing profiles and view state. The issue mentions removing these from anonymous access, so likely need to modify route guards or add authorization checks to reject anonymous users from modifying those resources. No linked PRs or maintainer responses provide additional guidance, so start by tracing the routes for profile management and view state updates.