Skip to content

Conversation

@ellie
Copy link
Member

@ellie ellie commented Aug 9, 2023

Under some sync circumstances, the record tails were being listed for other users. Beyond the existence of the tail, no data leaked

  1. When actually trying to fetch the record, the server responds with a 401
  2. Even if the above was not true, the client would not be able to decrypt the data

Tldr is that the index was not permissioned 100% correctly, but now is

@vercel
Copy link

vercel bot commented Aug 9, 2023

The latest updates on your projects. Learn more about Vercel for Git ↗︎

Name Status Preview Updated (UTC)
atuin-docs ✅ Ready (Inspect) Visit Preview Aug 9, 2023 10:46pm

@ellie ellie merged commit 925bf0e into main Aug 9, 2023
@ellie ellie deleted the ellie/fix-index-leak branch August 9, 2023 22:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants