logoalt Hacker News

anothercatlast Wednesday at 11:02 PM1 replyview on HN

Does this require authenticated access to the posthog api to kick off? In that case I feel clickhouse and posthog both have their share of the blame here.


Replies

nightpoollast Wednesday at 11:10 PM

It looks like the entire class of bugs here are "if you have access to Posthog's admin dashboard, you can configure webhook URLs that hit Posthog's internal services". That's not particularly surprising for a self-hosted system like the author's, but I expect it would pretty bad if you were using their cloud-hosted product.

show 1 reply