Skip to content

the root private key should not be used for sealing Biscuit tokens #20

@Geal

Description

@Geal

I'm not sure if it will result in a big vulnerability, but it would be better to have a dedicated secret key for this: https://github.com/PierreZ/record-store/blob/master/record-store/src/main/java/fr/pierrezemb/recordstore/auth/BiscuitManager.java#L80

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions