DEV Community

Discussion on: What's the Most Unusual Thing You've Discovered While Coding?

Collapse
 
tandrieu profile image
Thibaut Andrieu

Security of a whole portal was based on “Restriction”, not “Authorization”. Meaning your access was “restricted” depending on the profile stored in your cookie.
Remove the cookie, remove the restriction. BAM ! You are admin 😁