Skip to content

Secret key is not verified in scotty example #2

Open
@kvanbere

Description

@kvanbere

Operating system or device, package version, compiler version:
All

Issue description:
In the scotty example (examples/scotty) the key specified by KEY= on launch is not verified. If the incorrect key is specified on GitHub the example server doesn't care. This is a security risk and means that the scotty example should not be used in production.

Note: This is not applicable to the servant example(s), which verify the keys correctly.

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions