Throw an error if a custom Auth Secret has not been set #87
Labels
effort: low
impact: high
unblocks new usecases, substantial improvement to existing feature, fixes a major bug
Leaving the default Auth Secret makes it easy for Auth Tokens to be forged and attackers to gain access to a site.
This plugin should throw an Exception if the Auth Secret has not been set via filter or the constant.
The text was updated successfully, but these errors were encountered: