Please remember to verify users with their password #2

Open
opened 2026-03-22 05:08:31 +00:00 by CatAClock · 0 comments
Owner

Oh god please for the love of FUCK make sure to verify users please they can just make a cookie for username (which is very public knowledge) and it can end VERY FUCKING BADLY if you access the fediverse with the world's largest security hole!

Seriously! Mastodon takes in a username & password and outputs a fucking long-ass token for verification (or maybe that is generated apon account creation idk). Let's not introduce obvious flaws.

Oh god please for the love of FUCK make sure to verify users please they can just make a cookie for **username** (which is very public knowledge) and it can end VERY FUCKING BADLY if you access the fediverse with the world's largest security hole! Seriously! Mastodon takes in a username & password and outputs a fucking long-ass token for verification (or maybe that is generated apon account creation idk). Let's not introduce obvious flaws.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Reference: CatAClock/Socialite#2
No description provided.