Skip to content

[馃敶 FIXING A MAJOR VULNERABILITY 馃敶] How do we keep the Scratch session ID a secured confidential secret?聽#5

Description

@yoyomonem

Describe the question
We need to keep the Scratch session ID a secured confidential secret while also updating it in case it ever changes. But how?

@jayz3314 said:
The scratch session id is not in a secret, which means anybody can access it and use it for bad things.
(taken from #1)

NECESSARY MENTION: @ScratchCredit/developers

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

help wantedExtra attention is neededissue fixThis fixes an issue (it's a sub-issue or has its own issue)questionFurther information is requestedsub-issueThis is a sub-issue of an issue鈿狅笍 VULNERABILITY 鈿狅笍鈿狅笍 A vulnerability has been found 鈿狅笍馃敶 MAJOR VULNERABILITY 馃敶馃敶 A major vulnerability has been found 馃敶

Type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions