Comment 2 for bug 1375599

Revision history for this message
Ajaya Agrawal (ajayaa) wrote :

Hi Jeremy,

It doesn't leak as of now. But if someone get access to messaging infrastructure, then he can potentially intercept all the user data and would be able compromise their accounts by simply changing password. Or worse by getting an admin token he can potentially paralyze the whole infrastructure.

I don't see a use of user token in any component which would be consuming notifications.