3rd party apps showing all devices for restricted users

Criterion10 months ago

Hi

I have recently updated my traccar server. Did a clean install of traccar 5.8.

I am having an issue when users are logging using gps pro app available on play store.

Users are able to see and control all devices like an admin user.

I am not sure if there is some configuration issue.

Please advise.

Kaloyan Kanev10 months ago

Traccar have no responsibility to 3rd party apps.

Criterion10 months ago

I fully understand that.

I'm mentioning it because it can be a security flaw where non admin users are able to view and control all devices.

Track-trace10 months ago

@Criterion Yes, you would think that if a 3rd party app would be able to login as a normal user and have admin rights it would be a server side flaw.

So can you point your app to the tracar demo servers and check if you can reproduce it?

Track-trace10 months ago

Because its hard to believe that it is possible what you are telling. It would seem more obvious that you server configuration would not be correct or your normal user has admin rights.

Criterion10 months ago

I have done a clean install and changed the server port number.

Now everything is working fine.

I suspect this third party app has some inbuilt caching or something.

Changing server address to demo server does not reproduce the problem.

Thanks for your help