Hello.

I was testing my refer a friend feature and noticed that in the email received suggesting the product, that the zenid of the user who sent the referral was attached to the product link.

So, i couldn't find any threads on this, but are there any security concerns regarding this? If he/she who sent the referring link still had an active session, is it possible for the recipient to click on the link and be "logged-in" on the sender's account?