Join Discord
Powered by
qq, can users see their own SuperTokens ID without...
# security-discussion
c
coleski
07/28/2024, 9:37 PM
qq, can users see their own SuperTokens ID without me disclosing it to them?
r
rp_st
07/29/2024, 4:16 AM
Hey
@coleski
yea they can. The access token they are sent has the user id in it. In the payload.
c
coleski
07/29/2024, 4:18 AM
ah. can they alter it? im wanting something i can securely fetch data with as a key for non-sensitive but personal info
r
rp_st
07/29/2024, 4:18 AM
They can’t alter it. The access token verification will fail
c
coleski
07/29/2024, 4:18 AM
got it, ty
coleski
07/29/2024, 4:18 AM
i admire the dedication btw answering my dumb questions on a saturday and sunday night very thankful ❤️
r
rp_st
07/29/2024, 4:19 AM
No question is dumb 🙂 happy to help.
Previous
Next