Skip to content

[Security] Adding providerKey to AnonymousToken #11006

@carlalexander

Description

@carlalexander

I apologize if this is covered elsewhere. I couldn't find any mention in articles, docs or issues. Is there a specific reason why AnonymousToken doesn't get the providerKey while all other AbstractToken subclasses do?

I am trying, programatically, to determine which firewall emitted an AnonymousToken and saw that it was not stored in the token.

I can create a PR to add it. I just wasn't sure if there was a security issue related to it so figured I'd ask first.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions