🟡 [P1] Secure identity verification endpoint #290
Reference in New Issue
Block a user
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
/api/v1/federation/identity/verifyhas no auth guard. Anyone can call it.Location
apps/api/src/federation/identity-linking.controller.ts:49-52Required Fix
Add
@UseGuards(AuthGuard)and rate limiting.Priority
HIGH (P1) - Public endpoint