-
Notifications
You must be signed in to change notification settings - Fork 3.7k
Closed
Labels
EngineeringImprovementItem broken or needs improvement.Item broken or needs improvement.InternalRequires API changes or must be handled by Expensify staffRequires API changes or must be handled by Expensify staffReviewingHas a PR in reviewHas a PR in reviewWeeklyKSv2KSv2
Description
If you haven’t already, check out our contributing guidelines for onboarding and email contributors@expensify.com to request to join our Slack channel!
Action Performed:
- Open app
- Send API request Report_UpdateLastRead for Account A (left window), on Account B room using Account B credential.
& Change sequence number, Account A email and account number
Expected Result:
User should not be able to change read unread messages bypassing login
Actual Result:
When opening Expensify on new tab, you have unread messages on that room because of the Api request.
Workaround:
Unknown
Platform:
Where is this issue occurring?
- Web
Version Number: 1.1.23-0
Reproducible in staging?:
Reproducible in production?:
Logs: https://stackoverflow.com/c/expensify/questions/4856
Notes/Photos/Videos: Any additional supporting documentation
lastRead_c.mp4
Expensify/Expensify Issue URL:
Issue reported by: @K4tsuki
Slack conversation: https://expensify.slack.com/archives/C01GTK53T8Q/p1640135067456000
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
EngineeringImprovementItem broken or needs improvement.Item broken or needs improvement.InternalRequires API changes or must be handled by Expensify staffRequires API changes or must be handled by Expensify staffReviewingHas a PR in reviewHas a PR in reviewWeeklyKSv2KSv2