Answer the question
In order to leave comments, you need to log in
SPA user roles and Angular security
Rich RESTful backend, division of users by roles, a chain of middleware's, etc. I'm
interested in the issue of security, while I'm not very good at practicing Angular, and perhaps a noob question.
Is it safe in the JSON body to drive such fields as IsAdmin, Permissions lists for a specific user. Is it possible to somehow fake / get close to the client code so that it would be possible to force Angular to show, for example, the Admin menu, or something else forbidden for a particular user. It is clear that on the backend I will not let you do what is not allowed. Only the client hack on Angular is interesting
Answer the question
In order to leave comments, you need to log in
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question