Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Audit all requests to authn.io and ensure no credentials (cookies) are sent #108

Open
dlongley opened this issue Jun 15, 2022 · 0 comments

Comments

@dlongley
Copy link
Contributor

As an added security measure, we should ensure that no credentials (cookies) are sent to authn.io for any requests -- cookies (for browsers that need to use them to store credential handler registrations vs. local storage / indexeddb) should all just be stored locally and never leave the user's browser.

@dlongley dlongley changed the title Audit all requests to authn.io and ensure no credentials are sent Audit all requests to authn.io and ensure no credentials (cookies) are sent Jun 22, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant