trophy 0
Jan 2025 2 posts
Charlie 10 days ago edited 10 days ago
I've just noticed that profile routing seems to be handled through first level slugs, such that , for example, `https://sbox.game/login` takes you to a players profile

Easy to overlook, but this is a non-trivial security risk that can easily be solved by popping profiles down a level to /profile/[username] or /id/[username]

Not the end of the world, but worth patching up before things get crazy around here post-launch imo

p.s. forgive me if this is the wrong place for such a report, I wasn't sure where else to post

edit: I've just noticed that my profile URL is `https://sbox.game/u/thecoppinger` — I'm guessing the profile example I gave (/login) is a leftover from an earlier version of the site?
trophy 1120
Apr 2026 12 posts
No, these are organizations.
trophy 0
Jan 2025 2 posts
Understood—the point stands that this should be fixed to prevent it from being a vector for abuse
people
Log in to reply
You can't reply if you're not logged in. That would be crazy.