manojkumar3692 / Vuejs-Authentication

84 stars 38 forks source link

Role injection with DevTools console #7

Open adbci opened 6 years ago

adbci commented 6 years ago

Hello,

thanks for the good work. I only had to change the role in the devtools console to get access to another one. Is it normal? Imagine I'm a resident and I switch manually to admin role? Don't you think it's a serious issue? Is it possible in real environment?

Thanks for your point of view.

jongaspar commented 6 years ago

This is logic/gatekeeping that the back-end needs to do too