&&&&&problem, if I look up someone else datatoken , I could login as them. http://165.232.48.178/zfrikadev/homecareservice/6942e0ed9b795aa9b58d0414
zfrika
compare the datatoken in these two users. guest1 account : datatoken: 98e87823ae84bb9bc70521de7cebb51d814846d9eb9a3ae88e302e28438a7729 http://165.232.48.178/zfrikadev/profile/98e87823ae84bb9bc70521de7cebb51d814846d9eb9a3ae88e302e28438a7729 this information is the _id of the record. 6942e0ed9b795aa9b58d0414. http://165.232.48.178/zfrikadev/homecareservice/6942e0ed9b795aa9b58d0414 the _id does not expose the datatoken of the user. we can get send a message t