3rd party apps showing all devices for restricted users

Criterion2 years ago

Hi

I have recently updated my traccar server. Did a clean install of traccar 5.8.

I am having an issue when users are logging using gps pro app available on play store.

Users are able to see and control all devices like an admin user.

I am not sure if there is some configuration issue.

Please advise.

Kaloyan Kanev2 years ago

Traccar have no responsibility to 3rd party apps.

Criterion2 years ago

I fully understand that.

I'm mentioning it because it can be a security flaw where non admin users are able to view and control all devices.

Track-trace2 years ago

@Criterion Yes, you would think that if a 3rd party app would be able to login as a normal user and have admin rights it would be a server side flaw.

So can you point your app to the tracar demo servers and check if you can reproduce it?

Track-trace2 years ago

Because its hard to believe that it is possible what you are telling. It would seem more obvious that you server configuration would not be correct or your normal user has admin rights.

Criterion2 years ago

I have done a clean install and changed the server port number.

Now everything is working fine.

I suspect this third party app has some inbuilt caching or something.

Changing server address to demo server does not reproduce the problem.

Thanks for your help