2 ms·
> 1. you're not trusting anyone Sure you are. You're trusting the client to send you valid data. > 2. the UUID by itself doesn't authenicate or authorize any
by beeboobaa 3y ago
> 1. you're not trusting anyone
Sure you are. You're trusting the client to send you valid data.
> 2. the UUID by itself doesn't authenicate or authorize anything
Okay, better hope no one ever considers the UUID to be a unique randomly generated token.
Besides that, users might be tempted to submit "vanity" UUIDs if they get to decide their own identifiers, breaking assumptions about the system.
> 4. many non-trivial and/or CQRS/ES apps work like this
Cool, if your friends jump off a bridge, you gonna follow them?