DescriptionCurrently, the server doesn't check that the inviting user is authorised on the room they are inviting another user into (so, they could in fact, invite themselves).
In the longer-term, this will be less of an issue as that user wouldn't have the details needed to decrypt the messages, but it'd still be wise to close this angle .
Activity
2018-05-12 15:21:11
2018-05-12 15:21:11
2018-05-12 15:21:14
2018-05-12 15:22:13
View Commit | View Changes
2018-05-12 15:24:13
View Commit | View Changes