aboutsummaryrefslogtreecommitdiffhomepage
path: root/src/client/components/index.ts
diff options
context:
space:
mode:
authornsfisis <nsfisis@gmail.com>2025-12-30 22:12:04 +0900
committernsfisis <nsfisis@gmail.com>2025-12-30 22:12:04 +0900
commit953e6aeca4a1cf5dcba2148ab638a357cd6e60a0 (patch)
tree8bd3f373640eb18eb497d05caac958edce286d9e /src/client/components/index.ts
parentc2eb7513834eeb5adfa53fff897f585de87e4821 (diff)
downloadkioku-953e6aeca4a1cf5dcba2148ab638a357cd6e60a0.tar.gz
kioku-953e6aeca4a1cf5dcba2148ab638a357cd6e60a0.tar.zst
kioku-953e6aeca4a1cf5dcba2148ab638a357cd6e60a0.zip
fix(sync): verify card ownership before update in push
Previously, when updating an existing card during sync push, only the target deck ownership was verified. This allowed a user who knew another user's card ID to potentially update that card by specifying their own deck. Now the query joins with decks table to verify the existing card belongs to the current user. 🤖 Generated with [Claude Code](https://claude.ai/claude-code) Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
Diffstat (limited to 'src/client/components/index.ts')
0 files changed, 0 insertions, 0 deletions