Skip to content

Don't assume canonical encoding of macaroons/caveats#16

Open
btoews wants to merge 1 commit intomainfrom
lax-decoding
Open

Don't assume canonical encoding of macaroons/caveats#16
btoews wants to merge 1 commit intomainfrom
lax-decoding

Conversation

@btoews
Copy link
Contributor

@btoews btoews commented Jan 29, 2024

What is this, SAML? Re-encoding for signature validation opens the door for vulnerabilities. It also is a pain to make sure that implementations in other languages encode macaroons/caveats identically to Go.

What is this, SAML? Re-encoding for signature validation opens the door
for vulnerabilities. It also is a pain to make sure that implementations
in other languages encode macaroons/caveats identically to Go.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant