WorkNest is a portfolio project, but it is built to keep each organization's data apart, and security reports are welcome.
Please don't open a public issue for a security problem. Use GitHub's private "Report a vulnerability" option on the Security tab of this repository, or email the address on the author's GitHub profile. A short description and the steps to reproduce are enough.
I'll reply as soon as I can, and I'll say when it is fixed.
- Reading or changing another organization's data
- Getting around roles (a member doing what only admins can)
- Taking over an account, or getting a sign-in token or session
- Getting a paid plan without paying
- Payments run in Razorpay's test mode, so no real money moves.
- Uploaded files are private and are not scanned for content.