3 ms·
It is done entirely on the client. You can check the source code. Read more on scrt.link/security.
by stophecom 5y ago
It is done entirely on the client. You can check the source code. Read more on scrt.link/security.
- ALittleLight 5y agoBut if the key is added to the link itself then you could be storing the encrypted string and decrypting it after getting a request for a link that contained the key. I'm not accusing you of that - just saying there is no way to prove that's not happening.
- stophecom 5y agoThe part of the URL holding the encryption key is not sent to the server. https://stackoverflow.com/questions/14462218/is-the-url-fragment-identifier-sent-to-the-server https://stackoverflow.com/questions/14462218/is-the-url-frag... Don't take my word for it :) You can check all code that runs in your browser and check all requests made within the network tab.
- ALittleLight 5y agoOkay, nice! I withdraw my comments.