Skip to content

Require refreshed login in (cookie, JWT) for sensitive CRUD routes #11

@TinaHeiligers

Description

@TinaHeiligers

For end user actions such as payments, deletion of items, item addition etc, a fresh login token needs to be generated. We need to help the end user out by ensuring they are the ones actually making sensitive changes that, if done by someone that should not actually be authorized, would be harmful to the end user.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions