Restrict API based on permissions
Currently, users can abuse the API and gain information they do not have permission to.
Example:
If a user is in a server, they can see all voice/text channels via API, even if they do not have appropriate permissions to see them. (Note: They cannot see the contents of said channels, but _can_ see connected users in voice chats)
Problem:
While it may be against the rules to use the API in such a manner (or may not be, depends how you're using the API), that will not stop users from doing it.
Suggested solution:
The API should be more heavily restricted based on the permissions of the client that is interacting with it. If a user doesn't have permissions to see a channel, they should not be told, or be able to inquire about it's existence via the discord API.
Accedi per aggiungere un commento.
Commenti
0 commenti