Hacker News new | ask | show | jobs
by mkagenius 3029 days ago
> If the parameter is invalid, return nothing, rather than return all the credit cards

I don’t think that’s the bug here, bug here is the authorization check not being there.

That parameter is trivial to obtain using other ways even now.