An anonymous submitter showed The Daily WTF the production function used to validate authentication tokens. Its implementation contains a TODO comment and returns true, so every supplied token is accepted.

IsTokenValid
public bool IsTokenValid(string token)
{
 //TODO
 return true;
}

The application stores the authenticated user's identity separately when the session starts. That makes impersonating another user somewhat harder, according to the article, but the token check itself provides no authentication. Remy Porter published the item in the CodeSOD series on October 1, 2026.