Even though "User.email" is enforced as unique at signup, it is not a unique...
Even though "User.email" is enforced as unique at signup, it is not a unique field in the database. Let's use "User.id" instead. This also makes it more difficult to do a session stealing attack.
Showing
Please register or sign in to comment