proxy/request signers: request signers should also sign access token by jphines · Pull Request #179 · buzzfeed/sso

Skip to content

Navigation Menu

Sign in

Appearance settings

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Sign up

Appearance settings

Conversation

@jphines

Copy link

Contributor

@jphines jphines commented

Apr 17, 2019

Problem

We received a security report that request signatures do not sign access tokens if the proxy is configured to forward them. These access tokens should be signed by our various signature methods so upstreams can be ensured that these tokens have not tampered via a MITM attack.

@jphines jphines added bug

Something isn't working

security/low-sev labels

Apr 17, 2019

@jphines jphines self-assigned this

Apr 17, 2019

@jphines jphines merged commit 3f8de31 into master

Apr 17, 2019

@jphines jphines deleted the proxy-request-signatures-should-include-token branch

April 17, 2019 18:03

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Reviewers

1 more reviewer

@shrayolacrayon shrayolacrayon shrayolacrayon approved these changes

Reviewers whose approvals may not affect merge requirements

Assignees

@jphines jphines

Labels

bug

Something isn't working

security/low-sev

Projects

None yet

Milestone

No milestone

Development

Successfully merging this pull request may close these issues.

2 participants

@jphines @shrayolacrayon