Skip to content

X-User-Id can easily be forged #535

@vseae

Description

@vseae

What is the type of issue?

No response

What is the issue?

https://mpp.dev/guides/subscription-payments
According to the documentation, in subscription mode, the client actively passes the X-User-Id header, which the server then parses to associate the user's subscription information. However, this X-User-Id can easily be forged.
What is your recommended implementation standard for a production environment?

Where did you find it?

https://mpp.dev/guides/subscription-payments

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions