Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You should note the security model here sucks. You embed your diagram with the same unique Id that is used to edit it. However, editing isn't authenticated. So anyone who can see your diagram can figure out the edit page and alter it.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: