Giter Site home page Giter Site logo

insight's People

Contributors

alexlyp avatar andrewfhart avatar bechi avatar blaiseexpmore25 avatar cmgustavo avatar dabura667 avatar dajohi avatar eveiv avatar ionux avatar jcvernaleo avatar jyap808 avatar koirikivi avatar lennie avatar maraoz avatar martindale avatar matiu avatar pierrerochard avatar sandakersmann avatar saschad avatar slavik0329 avatar thesoftwarejedi avatar visvirial avatar wozz avatar yemel avatar

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

insight's Issues

Bug Report :- Path Traversal [CRITICAL]

Hello Team,
I have found path traversal attack on your website , so in this way attacker perform many attack to compromise your data. so you need to fix this issue asap.

Steps to Reproduce the issue :-
--->>Open this link

  1. https://wallet.decred.org/..%c0%af%7BFILE%7D

Now you see there some directory of your website.

I'm not try to exploit this issue because it's illegal. Before someone do this so please fix this issue.

let me know if you need more info !

I'm working as a Security researcher Individual, so this bug eligible for any bounty ?

looking forward your reply !

Regards
Chand

Rename dbits to atoms

They are referred to as atoms everywhere else in the software stack, so this should match as well.

Update logo

We are still using the old logo, should update to the new one.

Pruned tx is requested with /address/Ds... all tx fail to load

When a tx is not found via RPC request during Address.update it errors out incorrectly.

Appears that getTransaction in app/controllers/transactions.js has incorrect callback return.

Should return err and null txinfo, then above it should catch the err and carry on loading tx

Shows wrong block timestamp

Looking at this block, says Timestamp Apr 21, 2016 7:30:46 AM
https://mainnet.decred.org/block/00000000000027d17eb089a438675baa194bcda21029afa7a8692230f2b36f3d
transactions within it all say mined Apr 21, 2016 7:30:46 AM as well.

Yimp also shows Time 2016-04-21 16:30:46 for the same block
Blockhash: 00000000000027d17eb089a438675baa194bcda21029afa7a8692230f2b36f3d
http://yiimp.ccminer.org/explorer?id=1574&height=21267

But, here is the bug, https://mainnet.decred.org/blocks
going down the list, block 21267 says Apr 21, 2016 7:31:05 AM
and most all the other blocks listed look to have a skewed time as well.

Block 1 shows value error

As the title indicates, blocks 0 and 1 in the block explorer sometimes show "value error" for the block reward field.

I imagine this is because of the special nature of the blocks where the genesis block has no subsidy and the block 1 is the block in which all of the initial airdrop and dev coins were created.

Transaction layout suggestions

from sambiohazard on decred IRC: just a suggestion: can we have 2 collapsing section one for newly generated coins at top which contains coinbase and votes, and second with 0-20 sstx on top and then regular tx after that. i said collapsing section cuz mostly people are interested in seeing sstx IMO so they can collapse newly generated coins section, which should be on top so subsidies are visible easily.
also include dev subsidy in newly generated coins section. one more suggestion: current design is only showing txid, i think people recognize tx by their address generally.

Implementation feedback: Navigation

Hi,
I'll keep these issues specific to each case. Starting from the top then:

  1. The logo and navigation should vertically align with the content. First thing logo to the left, search bar being something trickier can either follow the grid or simply stay in the middle.

  2. Search field text:
    Font: Source Sans Pro, Regular
    Color: #5a6d81
    Size: 13 px

  • Centered to field
  • Hides when clicked upon
  • Type text begins aligned to left (next to icon)
  1. Page names and dropdown (Blocks, Status, mDCR/DCR)
    Color: #ffffff
    Hover: Can stay as it is
    Selected/Activated: Box background #132f4b

screen shot 2017-05-23 at 18 37 46

Design documentation for reference: https://www.notion.so/eeter/mainnet-decred-org-29098479211a49b0ae1fa3ec55b83537

show information about locked funds

The blockchain has information about which transactions / addresses contain locked funds. Currently this information is now shown. It may be going into an addresses Final Balance.

calendar selector is using UTC

The blocks page shows the block timestamp in normal time,
but the day on the left hand side of the page is in UTC,
and the pagination happens in UTC as well.
https://mainnet.decred.org/blocks

Other issues with the calendar selector are that it allows selecting of dates prior to Feb 8th for which there is no data. Also, when you open the calendar selector it defaults to todays date rather then the current date you are viewing.

Remove pagination by day

Sometimes when going to https://mainnet.decred.org/blocks
It will say, "No blocks yet."
Because it thinks its the beginning of the day,..as measures in UTC.
Other times it will only show a few blocks of data.
Remove pagination by day. Pagination should be for a set number of blocks.

Filter by transaction type

Feature request. Filter by transaction type.

In address view

  • Incoming
  • Outgoing

In block view,

  • Votes
  • Tickets
  • Transactions

false alerts, Double spent attempt detected

Many transactions will display Double spent attempt detected. From tx: xyz
But then clicking on the tx hash claimed, it says not found.
Since I am the owner of the input, I know that no double spent attempt was sent, so the alert is false.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.