DEV Community

Discussion on: Is it okay to expose MongoDB ObjectIds?

Collapse
 
robkenis profile image
Rob Kenis

The security post is indeed a little concerning, good catch! If you look at the documentation from version 3.0 for example, and version 4.0, it seems like the implementation of ObjectId has changed to use a random value instead of the machine-process combination.

Thread Thread
 
thomasstep profile image
Thomas Step

That's the missing piece. Nice find. I wonder if the motivation was to get rid of that potential threat. Thanks for the thoughts!