#97992: "Secret cards from other player are leaked "
Čeho se toto hlášení týká?
Co se stalo? Prosím vyberte níže
Detailní popis
-
• Která část pravidel nebyla dodržena adaptací hry na BGA
Secret cards from other players can be seen, because they are sent to the browsers of each player. This allows any cheater to get access to a lot of data (didn't check to which extent, but I suppose most of the stuff is accessible).
It is even leaked very shortly by some animations (that's how I got the idea to check). -
• Je vidět porušení pravidel na záznamu hry? Pokud ano, ve kterém tahu?
Each time a player put a card on the mine, getting a hidden one, it is temporarily visible with the animation.
• Jaký prohlížeč používáte?
Google Chrome v116
Historie hlášení
I don't know if everything is accessible or only certain moves related to the mine (quick look at the Websocket frames makes me think that it is everything, but not sure yet : I didn't try to understand them fully).
Advice : a security check should be done for this game, and then probably a big refactoring, as any information not visible to a player should NOT be sent at all to this player, even if not displayed.
This is a violation of the rules of the game. It should not be possible for the opponent to see the replaced card.
imgur.com/a/2ILsd4n
Doplňte tuto zprávu
- ID dalšího stolu / ID tahu
- Byla chyba odstraněna stisknutím F5?
- Objevila se tato chyba častěji? Pokaždé? Náhodně?
- Pokud máš snímek obrazvky zobrazující tuto chybu (doporučujeme!), můžeš použít Imgur.com pro nahrání obrázku a pak odkaz na tento obrázek na Imguru zkopírovat a vložit sem.

