Skip to content

Poll endpoint should require authorization #208

@FragLegs

Description

@FragLegs

The second recommendation from the final security audit:

As we note in Section 2.6, poll endpoint URLs
are not required to be secret, i.e., SETs could be requested by any party. For use cases requiring
confidentiality of SETs, we recommend mandating authorization at the poll endpoint.

Metadata

Metadata

Assignees

No one assigned

    Labels

    spec:SSFv1FinalIssues that must be fixed before we propose a spec to become a v1 final spec.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions