facg3 / MWM-Chat

this is room chat project for express week
0 stars 1 forks source link

you need to verify the token to check if user login #37

Open Walidmash opened 6 years ago

Walidmash commented 6 years ago

https://github.com/facg3/MWM-Chat/blob/86b2915bd7d778383b4d227a56668b791430906a/src/controllers/roomChat.js#L6

you just checking if user has token or not to determine if he is logged in or not, and thats a very easy way to be hacked

MahmoudMH commented 6 years ago

ما حليناهاش