Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ID Accessibility in API #723

Open
kevinbowie opened this issue Feb 6, 2025 · 0 comments
Open

ID Accessibility in API #723

kevinbowie opened this issue Feb 6, 2025 · 0 comments

Comments

@kevinbowie
Copy link

kevinbowie commented Feb 6, 2025

Halo kang Eko

Saya tidak begitu yakin bagaimana menyampaikannya,

tapi katakan lah saya memiliki User ID yg auto increment,
secara security apakah itu jika itu direturn misal pada response API?
krn terkadang ada 3rd party yg membutuhkan user_id nya misal utk analytic / chat yg dikirim oleh FE.

meski pun kenyataannya, informasi user bisa diketahui jika berhasil login. apakah itu hal yg perlu dikhawatirkan ?

atau case lain, API ny public spt utk track no resi (UUID), tp butuh user_id utk double verifikasi klo ini mmg dishare dr user lgsg.

apakah ID tsb lbh baik hny dikeep / diketahui BE saja? tidak boleh diekspos sama sekali?

gmn menurut kang eko? thanks before

@kevinbowie kevinbowie changed the title ID Visibility in API ID Accessibility in API Feb 6, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant