pocolifo / noter-backend

0 stars 0 forks source link

Email verification can be bypassed #28

Closed YoungerMax closed 11 months ago

YoungerMax commented 11 months ago

When the cookie is set, you can use https://jwt.io/ to decode the JWT get get the user ID, which is the email verification key. This bypasses the verification process