Open niehusst opened 2 months ago
never trust client input; don't blindly overwrite current db board state w/ whatever the client sends. A user could craft req such that entire board gets replaced w/ diff state if we dont perform backup validation server-side.
never trust client input; don't blindly overwrite current db board state w/ whatever the client sends. A user could craft req such that entire board gets replaced w/ diff state if we dont perform backup validation server-side.