-
Notifications
You must be signed in to change notification settings - Fork 4
Open
Description
What happened?
- A past-due context passed from the app that uses the SDK would create a massive, near-infinite TTL. Validation needed.
- Implement validation of the Expiration field in incoming envelopes. The peer should reject expired envelopes, improving security and resource usage.
- Prevents accidental or malicious use of extremely short or long TTLs.
- Response expiration should be based on the time remaining for the original request expiration.
Metadata
Metadata
Assignees
Labels
rmb-sdkbelongs to rmbbelongs to rmb