When I generate an explain query link to share with my team, I expect it to only be viewable by the people I send it to. However, the existing query plan links are very short, and extremely low entropy—there are only 140,608 possible plans with 3 character IDs! I was easily able to view other stored plans on the server by just guessing random 3-letter alphabetic IDs. Please update your ID system so that you have at least 64, and preferably 128, bits of entropy, to make it harder to enumerate random query plans.
When I generate an explain query link to share with my team, I expect it to only be viewable by the people I send it to. However, the existing query plan links are very short, and extremely low entropy—there are only 140,608 possible plans with 3 character IDs! I was easily able to view other stored plans on the server by just guessing random 3-letter alphabetic IDs. Please update your ID system so that you have at least 64, and preferably 128, bits of entropy, to make it harder to enumerate random query plans.