3 ms·
Am I understanding the article right: the endpoint would accept any email address and generate a valid JWT without verifying the caller owned the email address?
by nick-garfield 6y ago
Am I understanding the article right: the endpoint would accept any email address and generate a valid JWT without verifying the caller owned the email address?
If so, what extra validation did Apple add to patch the bug?