Skip to content

Conversation

@isaacagudo
Copy link

I haven't check yet https://www.npmjs.com/package/@dinoboff/ims-lti but it seem thats the ideal way to go. Another alternative, very naive is to check in any case whether the 'x-forwarded-proto' headers is set to HTTPS, an in this case asume that even if the actual protocol for the request is HTTP we should use HTTPS for checking the signature.

Check whether the 'x-forwarded-proto' headers is set to HTTPS, in this case asume that even if the actual protocol for the request is HTTP we should use HTTPS for checking the signature.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant