Skip to content

WebChat "default-user" causes shared user state #1344

@lauren-mills

Description

@lauren-mills

I noticed during some testing using UserState that each time I opened webchat it would pull down the same state object in each instance.

Webchat uses "default-user" as the id for all anonymous users which means all users will share the same user state. This seems like a security risk.

Can we change to use a random user id for all anonymous users?

Metadata

Metadata

Assignees

Labels

community-help-wantedThis is a good issue for a contributor to take on and submit a solutionfront-burnerp0Must Fix. Release-blockerp2Nice to havesize-s1 days or less

Type

No type

Projects

No projects

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions