• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

strongloop / loopback / 6056
90%
master: 90%

Build:
Build:
LAST BUILD BRANCH: chore/update-lts
DEFAULT BRANCH: master
Ran 30 Oct 2017 07:46AM UTC
Jobs 3
Files 36
Run time 4min
Badge
Embed ▾
README BADGES
x

If you need to use a raster PNG badge, change the '.svg' to '.png' in the link

Markdown

Textile

RDoc

HTML

Rst

pending completion
6056

push

travis-ci

bajtos
Fix "POST /change-password" for multi-user setup

Fix the code extracting current user id from the access token provided
in the HTTP request, to allow only access tokens created by the target
user models to execute the action.

This fixes the following security vulnerability:

* We have two user models, e.g. Admin and Customer

* We have an Admin instance and a Customer instance with the same
  id and the same password.

* The Customer can change Admin's password using their
  regular access token.

1818 of 2273 branches covered (79.98%)

3302 of 3668 relevant lines covered (90.02%)

9484.98 hits per line

Jobs
ID Job ID Ran Files Coverage
1 6056.1 30 Oct 2017 07:47AM UTC 0
90.02
Travis Job 6056.1
2 6056.2 30 Oct 2017 07:50AM UTC 0
90.02
Travis Job 6056.2
3 6056.3 30 Oct 2017 07:46AM UTC 0
90.02
Travis Job 6056.3
Source Files on build 6056
Detailed source file information is not available for this build.
  • Back to Repo
  • Travis Build #6056
  • 3996f56a on github
STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc