Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Issue secret key for reconnecting #8

Open
jclem opened this issue Jun 5, 2015 · 0 comments
Open

Issue secret key for reconnecting #8

jclem opened this issue Jun 5, 2015 · 0 comments

Comments

@jclem
Copy link
Member

jclem commented Jun 5, 2015

Currently, impersonating another user's ID (identity is another matter) is easy because anyone can exploit the reconnection feature with anyone else's ID. Instead, clients should be given a secret upon connecting that they can use to reconnect again in the future.

This key should probably be permanently tied to a single identity as well (unless it has expired?)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant