Creator Web bypass gamepass

You can enter to edit any gamepass as long as you have the gamepass id and number.

Expected behavior

I was helping my friend to edit a gamepass but he sent me the link to the creator and I told him that the link was incorrect, so I still went in and he let me edit it. The weird thing is that it is not from a group but from a profile.

Page URL: https://create.roblox.com/

A private message is associated with this bug report

4 Likes

I just tried to reproduce, and found out that I can go to the configure page for any gamepass on the create website, BUT when I click update changes, the changes will not update even though it sets “successfully updated”.

So you can’t really edit any gamepass. Only view the config page.

1 Like

Sure, it makes sense, but you still shouldn’t look at that information. It’s a small bug that can make things worse.

1 Like

Yup can confirm- purely visual bug though.

All information shown on the config page is shown publicly on the gamepass’s page.

The description, title, and price (if any).

1 Like

Indeed, although we should not have access to the gamepass configuration page as this is displayed on the website once the gamepass is published, we just have to wait for the staff to respond.

1 Like

Hi, thanks for flagging this; There are permission checks to verify updating a game pass though, which is why you can’t update them.

E: Actually, need to think about this more; the returned information is identical to the publicly available information on the pass details page, so functionally it doesn’t expose any functionality/info that it shouldn’t (that sales data is hidden), but it’s just very strange to be able to visit this url. Gimme a bit to think about what to do about this

2 Likes

You’re welcome, I hope this is helpful.

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.