logoalt Hacker News

ginkotoday at 9:13 AM1 replyview on HN

There's lack of security theater and there's:

> All "access control" logic lived in the JavaScript on the client side, meaning the data was literally one curl command away from anyone who looked.

They are not the same thing.


Replies

chrisjjtoday at 9:24 AM

You've got to wonder from where did the "AI" parroted that.

show 1 reply