How to securely setExternalUserId() in OneSignal?

Viewed 832

I'm setting up OneSignal on my website.

As far as I can see, there are 2 ways I can associate a push subscription with my user ID:

  • I can call OneSignal.getUserId(), which returns a UUID, and make an authenticated call to my web server to associate this UUID with my logged in user on my server
  • I can call setExternalUserId() to send the logged in user ID and associate it with the subscription on OneSignal servers

The first option is perfectly secure, as one could only hijack my client-side code to send an invalid subscription ID (or another valid subscription ID they have created), which is not a big deal.

The second option though, feels totally unsecure: anyone could hijack the client-side code to send any valid user ID and associate it with its subscription, and therefore receive notifications on behalf of another user.

Is there a way to securely use setExternalUserId() while preventing a user from associating their subscription with another user?

The only secure scenario I can think of is if my users had UUIDs as well, instead of sequential IDs, and these UUIDs were kept secret (i.e. never exposed publicly on the website).

Any other scenario I can think of sounds plain insecure.

Did I miss something?

0 Answers
Related