#97992: "Secret cards from other player are leaked "
這是關於哪方面的案件?
發生什麼事? 請從下方選擇
細節描述
-
• 遊戲規則的哪部分在 BGA 版本有所錯漏?
Secret cards from other players can be seen, because they are sent to the browsers of each player. This allows any cheater to get access to a lot of data (didn't check to which extent, but I suppose most of the stuff is accessible).
It is even leaked very shortly by some animations (that's how I got the idea to check). -
• 這項違反規則之處可否在遊戲重播中看到?若可以是在哪步?(重播時左上角資訊)
Each time a player put a card on the mine, getting a hidden one, it is temporarily visible with the animation.
• 你的瀏覽器是什麼?
Google Chrome v116
案件沿革
I don't know if everything is accessible or only certain moves related to the mine (quick look at the Websocket frames makes me think that it is everything, but not sure yet : I didn't try to understand them fully).
Advice : a security check should be done for this game, and then probably a big refactoring, as any information not visible to a player should NOT be sent at all to this player, even if not displayed.
This is a violation of the rules of the game. It should not be possible for the opponent to see the replaced card.
imgur.com/a/2ILsd4n
為本案件添加內容
- 其他同樣狀況的桌號/步數
- 按 F5 是否解決了這個問題?
- 問題是否發生了好幾次?每次都發生?時好時壞?
- 建議將此錯誤的螢幕截圖上傳到 Imgur.com 並轉貼連結。

