Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Security of the post API #9

Open
GeeF opened this issue Mar 23, 2017 · 4 comments
Open

Security of the post API #9

GeeF opened this issue Mar 23, 2017 · 4 comments

Comments

@GeeF
Copy link

GeeF commented Mar 23, 2017

Maybe I'm missing something, but from what I see, the permission to post data for a specific sensor node is solely based on its id? That could potentially be bad, as you can get ids that are activated pretty easily.

@ricki-z
Copy link
Member

ricki-z commented Mar 23, 2017

Can you tell me how to get another activated id beside your own?

@GeeF
Copy link
Author

GeeF commented Mar 24, 2017 via email

@ricki-z
Copy link
Member

ricki-z commented Mar 24, 2017

The "feinstaub-api" and the server generating these graphics are independent.
Not every sensor in the "feinstaub-api" is sending to madavi api. And some of the sensors shown there aren't sending to "feinstaub-api". Even some of the sensors not marked red if they are "known".
Example: esp8266-906538 is shown on madavi.de but should be denied by api.luftdaten.info

@GeeF
Copy link
Author

GeeF commented Mar 27, 2017 via email

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants