-
Notifications
You must be signed in to change notification settings - Fork 4
Open
Description
Session IDs are being directly saved to the database to identify participants. This is dangerous because session ID's might accidentally be leaked when fetching responses and session ID's can be used to impersonate users.
Solution: save hashes of sessionIDs instead, or find some other solution.
Reactions are currently unavailable