#Request returns to homepage

1 messages · Page 1 of 1 (latest)

frigid peak
#

Show your headers.

#

Also. You don’t “log in” to APIs.

grim galleon
frigid peak
#

I also wouldn’t be putting so much validation around the email and password fields, as you’re just leaking whether an email actually exists in the database, and the minimum and maximum length of passwords, which just means an attacker can narrow their efforts.

grim galleon
grim galleon
frigid peak
grim galleon
#

years is an exaggeration but days

#

and if I increase it to 12 characters, this becomes impossible