Skip to content

[🔴 FIXING A MAJOR VULNERABILITY 🔴] How do we keep the Scratch session ID a secured confidential secret? #5

@yoyomonem

Description

@yoyomonem

Describe the question
We need to keep the Scratch session ID a secured confidential secret while also updating it in case it ever changes. But how?

@jayz3314 said:
The scratch session id is not in a secret, which means anybody can access it and use it for bad things.
(taken from #1)

NECESSARY MENTION: @ScratchCredit/developers

Metadata

Metadata

Labels

help wantedExtra attention is neededissue fixThis fixes an issue (it's a sub-issue or has its own issue)questionFurther information is requestedsub-issueThis is a sub-issue of an issue⚠️ VULNERABILITY ⚠️⚠️ A vulnerability has been found ⚠️🔴 MAJOR VULNERABILITY 🔴🔴 A major vulnerability has been found 🔴

Type

Projects

No projects

Relationships

None yet

Development

No branches or pull requests

Issue actions