eduvpn / apple

app for iOS and macOS
Other
62 stars 18 forks source link

Do not reuse tokens for "Institute Access" at other institute access servers #195

Closed ghost closed 4 years ago

ghost commented 4 years ago

It seems the apps also try to use tokens obtained from a "institute access" server at other servers, just like for "secure internet". This is very wrong, not sure how it got to be this way?!

https://github.com/eduvpn/documentation/blob/v2/INSTANCE_DISCOVERY.md#authorization

jeroenleenarts commented 4 years ago

This was changes in the documentation end of august. The current logic is based on a previous version of the discovery documentation.

Also the "weekly refresh" is NOT in the codebase yet.

ghost commented 4 years ago

This was changes in the documentation end of august. The current logic is based on a previous version of the discovery documentation.

Not it wasn't. It was always there, just explained differently. It has to do with the "authorization_type" that is set to "local" in the discovery file. Look through the old revisions if you want.