3 ms·
Sounds like a storm in a teacup if indeed the endpoint is served over TLS.
by dthakur 11y ago
Sounds like a storm in a teacup if indeed the endpoint is served over TLS.
- balls187 11y agoWell, no. Rather it's a threat vs vulnerability case. There exists a vulnerability, because the Peach tokens (seemingly) never expire, and thus are vulnerable to replay attacks. However, because authorization uses TLS, it's very unlikely it will be exploited, because TLS mitigates MITM attacks.