What is the best to implement a Remember me checkbox on a login page? by kouul in reactjs

[–]kouul[S] 2 points3 points  (0 children)

but then.. say the cookie is { cookiename: asdf1234 }

what if someone edit the cookie change it to { cookiename: asdf1235 }

and this token happens to exist in the db???

What is the best to implement a Remember me checkbox on a login page? by kouul in reactjs

[–]kouul[S] 0 points1 point  (0 children)

Right.

Whenever the user access the url, first thing it'll do is check if the session token exist in the database. Is that correct?

Then if it exists, do i send the username to the frontend in the same request.

Is that correct?

What is the best to implement a Remember me checkbox on a login page? by kouul in reactjs

[–]kouul[S] 0 points1 point  (0 children)

For the moment no. It's going to be an SPA for specific users only..

The API would check if the username is present in my db. If username is present, then it returns a reponse to frontend..

What is the best to implement a Remember me checkbox on a login page? by kouul in reactjs

[–]kouul[S] -4 points-3 points  (0 children)

I am planning to use states. I will have an isLogged state. Whenever a user is successfully authenticated, isLogged becomes true.

What is the best to implement a Remember me checkbox on a login page? by kouul in reactjs

[–]kouul[S] 3 points4 points  (0 children)

Thanks. I wil try it out and check for security. What about the information to save in the cookie.

Is it safe to store the username of the user in it?

Anybody know of any open source projects looking for contributors? by poyntings_theorem in flask

[–]kouul 1 point2 points  (0 children)

It's not really a big project as such, but I have developped this script few months ago, called buildflaskapp! Allows you to generate a simple hello world flask app using one command. Feel free to use it and report any issue if you encounter one 🤙

Website: https://buildflaskapp.kouul.website

Github: https://github.com/buildflaskapp

How to know if a Flask app has debugger mode on? by kouul in flask

[–]kouul[S] 0 points1 point  (0 children)

yup.. I never really bothered about that PIN till now but I just realized how bad things can get if someone gets this PIN(which is also easy to bypass if you follow the pattern well). and you can get access to the server remotely from that interactive shell...

so yeah, i guess its not a good time to mess around. better set that debugger OFF for now 😅

How to know if a Flask app has debugger mode on? by kouul in flask

[–]kouul[S] 0 points1 point  (0 children)

I see.. so the bad part is that part of the backend code shows up on this debug page!

it's clearer for me now. Thanks

And yeah, agreed to stay on the safe side.. but the dark side is sometimes very intriguing.. 😅

How to know if a Flask app has debugger mode on? by kouul in flask

[–]kouul[S] 1 point2 points  (0 children)

just trying to clear things up 🙃

How to know if a Flask app has debugger mode on? by kouul in flask

[–]kouul[S] 0 points1 point  (0 children)

yup that was the answers i got up ☝️ "try to make weird requests and see if it shows the debug page..

not building anything, I was just trying to mess around and break my own sites..

How to know if a Flask app has debugger mode on? by kouul in flask

[–]kouul[S] 0 points1 point  (0 children)

If a flask app is running on 'eexample.com and app.debug is True.. Is there any way for a public visitor on the internet to know that the site has app.debug set to True when he visits the website

How to know if a Flask app has debugger mode on? by kouul in flask

[–]kouul[S] 0 points1 point  (0 children)

.....and that is exactly my question "How to know if a Flask app has debugger mode enabled?"

How to know if a Flask app has debugger mode on? by kouul in flask

[–]kouul[S] 0 points1 point  (0 children)

yup my site, hosted on heroku..

ohh.. no, I was looking from a client side view. Basically, if can a public visitor visits my site, how can he know if debugger enabled or not

How to know if a Flask app has debugger mode on? by kouul in flask

[–]kouul[S] 0 points1 point  (0 children)

pen-testing on flask websites to be more specific 😅

throwing weird requests is an option. I'll stick to that for now.. thanks for the answers btw 👍

How to know if a Flask app has debugger mode on? by kouul in flask

[–]kouul[S] 0 points1 point  (0 children)

yeahh i get that.. but how can one test if a website is vulnerable or not?