Skip to content

Conversation

@jphines
Copy link
Contributor

@jphines jphines commented Apr 17, 2019

Problem

We received a security report that request signatures do not sign access tokens if the proxy is configured to forward them. These access tokens should be signed by our various signature methods so upstreams can be ensured that these tokens have not tampered via a MITM attack.

@jphines jphines added bug Something isn't working security/low-sev labels Apr 17, 2019
@jphines jphines requested a review from shrayolacrayon April 17, 2019 17:06
@jphines jphines self-assigned this Apr 17, 2019
@jphines jphines merged commit 3f8de31 into master Apr 17, 2019
@jphines jphines deleted the proxy-request-signatures-should-include-token branch April 17, 2019 18:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working security/low-sev

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants