Skip to content

Dangerous Participant IDs #281

@lydia-schow

Description

@lydia-schow

Session IDs are being directly saved to the database to identify participants. This is dangerous because session ID's might accidentally be leaked when fetching responses and session ID's can be used to impersonate users.

Solution: save hashes of sessionIDs instead, or find some other solution.

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions