- Passwords must never be sent to the client, all login verification must be handled exclusively on the backend.

- IsAdmin must be stored in a server-controlled, encrypted session variable.

- A great security practice is to hash passwords before storing them in the database.

congratulations to your son on his first website !

Reply to this note

Please Login to reply.

Discussion

Thanks for taking the time out to check and provide this feedback. We are grateful in this house to know about NOSTR and have such a helpful community.

I'll pass on the congratulations.

Cheers!