SessionInit can be bypassed

Issue #5 resolved
Rob Eden repo owner created an issue

A malicious client can bypass the SessionInit message and send other messages immediately, including invocations. Invocations in this state wouldn't have user context associated with them, which could be a privilege escalation in some circumstances.

Comments (2)

  1. Log in to comment