Have you considered that discussing API design decisions regarding security in a public forum is a bad decision of your own?
After literally 10 seconds on the site, I found this: https://bolt.com/security
Have you considered that discussing API design decisions regarding security in a public forum is a bad decision of your own?
After literally 10 seconds on the site, I found this: https://bolt.com/security
Your post tried to chastise him for calling out a vulnerability, and then tried to shame him for not quietly emailing their security team. Chances are if someone were a bad actor they would have: A) seen that themselves outside of his message, or B) Found out through sheer luck and brute force
If anything, the poster mentioning it invites the team to fix it before someone exploits it. It's worse to blunder on a hole someone told you was 1.5km down the road, so hopefully they either address it or fix it
My concern is not a security issue or vulnerability on their site or service. I am concerned that a processes they are recommending may not be safe, and if I am incorrect (I still feel that I may be missing something), I feel that a response may be insightful to others.