Forum Discussion
PaoloT
10 years agoLithium Alumni (Retired)
Hi grahamgatus
out of curiosity, why this behavior is identifier as a risk? I would normally say that in this situation, this is the desired behavior. If a user is logged in in their browser, they should be able to see data that is avaialble to their account.
Thanks,