4 ms·
"Never trust the client"
by Firehed 14y ago
"Never trust the client"
- nessus42 14y agoThe session information is cryptographically signed, so you don't have to trust it! These stateless server frameworks are just using the client as a state cache.