Skip to content

Login tokens work on anywhere #72

@benloh

Description

@benloh

While it's very cool that the login tokens that are always the same every time you generate them, it does create a security loophole. I can go to any Net.Create install and use my login ID to get in.

This is not that much of an issue now with local installs, but for the future, we probably want to introduce some kind of seed value so that I can't use "MOD-BUGLE-LME" on any Net.Create site.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions