Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Hawk responses are not checked for authorization #807

Closed
kumar303 opened this issue Feb 11, 2014 · 1 comment
Closed

Hawk responses are not checked for authorization #807

kumar303 opened this issue Feb 11, 2014 · 1 comment

Comments

@kumar303
Copy link

Unless I missed it in the source, request's Hawk support sends a valid request header but it does not verify the incoming response. This should at least be documented since developers will be creating a security hole in their client code.

This is how responses are verified with Hawk:

@stale
Copy link

stale bot commented Nov 23, 2018

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

@stale stale bot added the stale label Nov 23, 2018
@stale stale bot closed this as completed Nov 30, 2018
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants