SUMMARY:
Right now the spec provides no guidance on the maximum size of a secret (or
a verify token). This should be specified.
RELEVANT SECTION: 6.1
~128 bytes seems reasonable for both (enough for hashes of various kinds).
But maybe we could allow for 300 or so to be more futureproof?
Original issue reported on code.google.com by bslatkin on 28 Jan 2010 at 7:15
Original issue reported on code.google.com by
bslatkin
on 28 Jan 2010 at 7:15