Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Verify requests for user information #142

Open
dpopp07 opened this issue Apr 3, 2018 · 0 comments
Open

Verify requests for user information #142

dpopp07 opened this issue Apr 3, 2018 · 0 comments

Comments

@dpopp07
Copy link
Collaborator

dpopp07 commented Apr 3, 2018

Right now, a token assigned by Auth0 will allow access to any route and therefore any data in the database that can be retrieved by the API. A user, with their own token, should only be able to access user data for themselves, but not for any other users. This could be tricky but it worth looking into.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant