Mobile app lets users circumvent role limitations - should respect role permissions
Posted: Tue Jul 08, 2025 8:31 am
At the moment, using the mobile app as a restricted user lets you circumvent some security related restrictions.
Specifically in my case, we have a sub-account for the cleaner. The cleaner is set to the role "Cleaner" which results in being able to look at the names and dates of the guests for the next stays, but not at the prices and of course not the messages we exchange with the guests - at least when being logged in via browser.
It now occured to me that the cleaner can indeed access the prices charged for the stay and also access the guest's communication when using the mobile app! The security settings connected to the role are not taken into account when using the mobile app. This is fatal to me because it violates some data privacy regulations in people seeing information that they are not entitled to see (internal vs. external).
Specifically in my case, we have a sub-account for the cleaner. The cleaner is set to the role "Cleaner" which results in being able to look at the names and dates of the guests for the next stays, but not at the prices and of course not the messages we exchange with the guests - at least when being logged in via browser.
It now occured to me that the cleaner can indeed access the prices charged for the stay and also access the guest's communication when using the mobile app! The security settings connected to the role are not taken into account when using the mobile app. This is fatal to me because it violates some data privacy regulations in people seeing information that they are not entitled to see (internal vs. external).