treblle-laravel icon indicating copy to clipboard operation
treblle-laravel copied to clipboard

Discussion around api_token provided in package

Open bhushan opened this issue 3 years ago • 1 comments

  • login and registration routes should not need token
  • once we login or register we should get token in response specific to that user..
  • then this token should be used to create projects ..

Not sure how that token is scoped in backend.. it might be security threat

Want to raise discussion around this topic so if needed it can be addressed..

bhushan avatar Jan 11 '22 16:01 bhushan

@bhushan I'm on this. I'll have this solved by tomorrow!

cindreta avatar Jan 11 '22 17:01 cindreta