Skip to content

Would it be a security issue adding hashedPassword to getUserAttributes #1509

Answered by pilcrowonpaper
rwieruch asked this question in Help
Discussion options

You must be logged in to vote

I would avoid doing that. You can leak user password hashes if you have an endpoint that returns the entire user object (worse if it's public)

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@rwieruch
Comment options

Answer selected by rwieruch
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Help
Labels
None yet
2 participants