3 ms·
It boggles my mind how they're not absolutely checking the user & conversation id for EVERY message in the queue given the possible sensitivity of the requests.
by 19h 4y ago
It boggles my mind how they're not absolutely checking the user & conversation id for EVERY message in the queue given the possible sensitivity of the requests. How is this even remotely acceptable?
In the one reddit post first surfacing this the user saw conversations related to politics in china and other rather sensitive topics related to CCP.
This can absolutely get people hurt and they absolutely must take this serious.
- zaroth 4y agoIt doesn’t boggle my mind at all. Session data appears, and is used to render the page. Do you verify every time the actual cookie and go back to the DB to see what user it pointed to? No, everyone assumes their session object is instantiated with the right values at that level of the code.