Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Make sure users can only submit as themselves #40

Open
oliverjam opened this issue Jan 28, 2022 · 0 comments
Open

Make sure users can only submit as themselves #40

oliverjam opened this issue Jan 28, 2022 · 0 comments

Comments

@oliverjam
Copy link

const SELLER_ID = `SELECT id FROM devpop_users WHERE devpop_users.name = ($1)`;

Rather than using a user-submitted name (which anyone can guess/fake), you should use the sid from the cookie to look up the seller_id from the sessions table. That way users can only ever submit as themselves, and you can guarantee there will always be a valid user

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant