duanbinren8906 2018-08-01 23:09
浏览 36

如何在REST API中更新用户映像的安全性

I've been learning REST API for couple months for my applications. I built a project which have login, register, reset password, change password. But I have a logic trouble at updating user image.

For example; when I change the user password I use this; /api/user/updatePassword/{email}/{token}/{password}

I validate code(token) from email. If its true and token not expired, I change! (By the way token is the code that I send to user, not token actually)

But I don't have an option in user photo. When user use backend like; "change the user photo which has this e-mail" may occur security problems as API.

How can I get through this and what is the best practice?

(I use PHP Slim framework and MySQL)

  • 写回答

0条回答 默认 最新

    报告相同问题?

    悬赏问题

    • ¥100 支付宝网页转账系统不识别账号
    • ¥15 基于单片机的靶位控制系统
    • ¥15 AT89C51控制8位八段数码管显示时钟。
    • ¥15 真我手机蓝牙传输进度消息被关闭了,怎么打开?(关键词-消息通知)
    • ¥15 下图接收小电路,谁知道原理
    • ¥15 装 pytorch 的时候出了好多问题,遇到这种情况怎么处理?
    • ¥20 IOS游览器某宝手机网页版自动立即购买JavaScript脚本
    • ¥15 手机接入宽带网线,如何释放宽带全部速度
    • ¥30 关于#r语言#的问题:如何对R语言中mfgarch包中构建的garch-midas模型进行样本内长期波动率预测和样本外长期波动率预测
    • ¥15 ETLCloud 处理json多层级问题