Skip to content

Security Concerns #14

@seanhandley

Description

@seanhandley
  1. Vulnerable to script/html injections
  2. Vulnerable to session replay i.e. if I record a post request to add a fic, then log out and clear my cookies, I can still add a fic as an authenticated user by replaying the captured request. Clearly, this bad!

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions