Council Record
Approved Decision
Users who aren't logged in can view the Companion tab via ?terminal=companion when maintenance mode is disengaged, violating auth checks for display on the client side. Currently the Terminal is in maintenance mode preventing this, and upon further investigation they cannot do anything at all in the Companion tab so this is mostly a auth and client side component rendering issue. This can be fixed with a simple auth check in the URL parameter handling so that when users try to access `?terminal=companion` without being logged in, they're redirected to the overview tab instead. Due to maintenance mode being active this exploit is ineffective, however, it should be patched immediately upon the receipt of this proposal.
This proposal was approved by the Council.
Showing 5 of 5 total voters
No votes