|
|
|
|
|
by tyleraldrich
2852 days ago
|
|
But... that's not really something you _have_ to avoid. Check permissions, if they fail the test -> http401 (for an API) or some user-friendly redirect. Something similar to this is how things work without JWT currently, so it's only a problem if you make it one. |
|