notp icon indicating copy to clipboard operation
notp copied to clipboard

Why check process.env.NODE_ENV?

Open coolaj86 opened this issue 9 years ago • 1 comments

I'd like to be able to casually run my own tests and examples without explicitly setting NODE_ENV.

I don't see a security benefit to this.

If the user of this library is somehow exposing the options object to a client they can already arbitrary adjust the window size to something like 100,000 which is just as insecure, so there's no security benefit.

In fact, I just tested with a window of 100,000 and an arbitrary token 957 124 and in in 5 out of 10 trials each taking about 2 seconds I was able to verify.

coolaj86 avatar Oct 07 '15 17:10 coolaj86

This was intended as more of a warning. Rather than removing the error completely, how about just logging a warning message?

guyht avatar Oct 08 '15 02:10 guyht