Allow/encourage dst/fmt to be specified in secret #9
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Also, allow the secret to allowlist these if they are to be put in request-time params.
The dst/fmt will usually be knowable at the time the secret is created and they usually wont need to vary between requests. Allowing them to be specified at request-time gives room for attackers to discover ways to get the target service to reflect back the plaintext secret in a response.