Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

wooAttendees accessible without auth! #33

Open
sn3h opened this issue Aug 4, 2021 · 0 comments
Open

wooAttendees accessible without auth! #33

sn3h opened this issue Aug 4, 2021 · 0 comments

Comments

@sn3h
Copy link

sn3h commented Aug 4, 2021

Hi, I am not sure if I am doing everything right, but it seems to me that Attendees are accessibel without any authorization with graphql.

For example:

orders{
nodes{
total
date
status
billing {
... all fields
}
}
}

returns "orders": {
"nodes": []
},

but

wooAttendees(first:100) {
edges{
node{
id
title
order{
total
date
status
billing {
... all fields
}

returns all the data even to anonymous user. This has to be private and accesibel only after authorization.

Is there some way to set this up? thanks

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant