mirror of
https://github.com/we-promise/sure.git
synced 2026-05-08 13:14:58 +00:00
DemoFamilyRefreshJob runs daily via cron and recreates a demo family from scratch. This is a managed-mode-only feature (the public hosted instance), but the job had no app_mode guard, so self-hosted instances were also creating and refreshing a demo family every day. This results in every self-host instance of sure getting the demo family with the well-known credentials created. It may be worth considering a separate one-time fix that deactivates the demo family users, and/or entries in the release notes or a separate security advisories alerting users that they need to deactivate the demo users.