Dec 4, 2018 01:04:57 AM by Valeria B
Heya,
A while ago, while typing in the upwork URL to log in and check my messages, I noticed something odd.
Can you spot it?
( hint: take a look at the messages URL )
Yes, you read that right.
Upwork's official messages URL apparently is:
https://upwork.com/messages/whatever-this-**bleep**-is
I thought maybe I had accidentally typed in that URL somehow ( although I would definitely remember typing THAT! ) but sure enough, if you type that address in your browser or click on the link above it will lead you to your messages.
I understand that URLs should not contain sensitive information since it can open the door to vulnerabilities, but maybe someone could have thought of a better placeholder text? I'm very surprised this has been overlooked and nobody at UpWork has caught it yet.
Anyways, does this appear for anyone else?
Has anyone else noticed it?
I'm curious to hear what you guys think.
Solved! Go to Solution.
Dec 4, 2018 01:56:24 AM by Goran V
Hi Valéria,
I tried to replicate the URL on my end but was not able to. I will escalate this to our technical team to investigate it further and one of our team members will reach out to you via ticket with more details. Thank you.
Dec 4, 2018 01:26:17 AM by Petra R
@Valéria B wrote:
I thought maybe I had accidentally typed in that URL somehow ( although I would definitely remember typing THAT! ) but sure enough, if you type that address in your browser or click on the link above it will lead you to your messages.
It doesn't for me. It takes me to the messages page but won't load, in exactly the same way as
https://www.upwork.com/messages/my-hamster-ate-my-cat does for example.
Dec 4, 2018 01:56:24 AM by Goran V
Hi Valéria,
I tried to replicate the URL on my end but was not able to. I will escalate this to our technical team to investigate it further and one of our team members will reach out to you via ticket with more details. Thank you.