4 ms·
Also the example PHP code doesn't validate the age of the passed timestamp so you could just replay a "signature" indefinitely... Given that, you might as well
by kam 7y ago
Also the example PHP code doesn't validate the age of the passed timestamp so you could just replay a "signature" indefinitely...
Given that, you might as well just use an unchanging token or Basic Auth. Assuming https, that wouldn't be terrible for this kind of use case. But put it in an Authorization header, not in a query parameter, so it doesn't end up in logs.
- grenoire 7y agoWell, the app has to support it, so you're down to the will of the developer. Sounds like a cool little thing, but wouldn't mind a standard to use on non-mobile platforms.
- re_dmitriy 7y agoThe documentation says it's a test of your choice.