But, you can just update your own product's `isApprovedByAdmin` field to true, bypassing this protection entirely.
But, you can just update your own product's `isApprovedByAdmin` field to true, bypassing this protection entirely.
When creating an order, your client sends a request to /api/v1/order/makeStripePayment, which would be fine, except for the fact that you provide which product you want & the price of it.
Server-side validation, what's that?
When creating an order, your client sends a request to /api/v1/order/makeStripePayment, which would be fine, except for the fact that you provide which product you want & the price of it.
Server-side validation, what's that?