Skip to content

Conversation

jeskew
Copy link
Contributor

@jeskew jeskew commented Dec 14, 2016

This header can be set or altered by a load balancer and is therefore unsafe to sign. Should a user provide this header before the SDK signs the request, there's a chance the header value (and thus the expected signature) could be changed in-flight.

/cc @chrisradek

@coveralls
Copy link

Coverage Status

Coverage remained the same at 88.147% when pulling 062d37a on jeskew:fix/leave-trace-id-header-unsigned into 6ffe8fe on aws:master.

1 similar comment
@coveralls
Copy link

coveralls commented Dec 14, 2016

Coverage Status

Coverage remained the same at 88.147% when pulling 062d37a on jeskew:fix/leave-trace-id-header-unsigned into 6ffe8fe on aws:master.

Copy link
Contributor

@chrisradek chrisradek left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@jeskew jeskew merged commit 8cbdf4d into aws:master Dec 15, 2016
@jeskew jeskew deleted the fix/leave-trace-id-header-unsigned branch December 15, 2016 23:14
@lock
Copy link

lock bot commented Sep 28, 2019

This thread has been automatically locked since there has not been any recent activity after it was closed. Please open a new issue for related bugs and link to relevant comments in this thread.

@lock lock bot locked as resolved and limited conversation to collaborators Sep 28, 2019
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants