Can other users not just change the userId in the local cookie to something else and then get other users info from the api? In my case todos
Well, if you've set up your back-end properly, they won't be able to do that
Are you sure you want to hide this comment? It will become hidden in your post, but will still be visible via the comment's permalink.
Hide child comments as well
Confirm
For further actions, you may consider blocking this person and/or reporting abuse
We're a place where coders share, stay up-to-date and grow their careers.
Can other users not just change the userId in the local cookie to something else and then get other users info from the api? In my case todos
Well, if you've set up your back-end properly, they won't be able to do that