Hacker News new | ask | show | jobs
by matthewowen 5000 days ago
I don't get this. Ensuring that users can't edit/access the profiles of other users is trivial in most frameworks.

It shouldn't be something that slips through testing. If you aren't doing that from the start, something is seriously wrong with how you're building out your application.