ks-hl/AuxProtect

[Privacy Issue] Copy IP in a:session with denied permission

Daechler opened this issue · 1 comments

You can copy the IP of a user with a:session, although the permission to do so has been denied.

Recreate:

  1. deny the auxprotect.lookup.action.session.ip permission
  2. make a lookup (e.g. /ap lookup user:Daechler action:session)
  3. click on [REDACTED]
  4. you have successfully copied the IP
ks-hl commented

Good catch. Will fix soon