gabrielg / mail_to_hip_chat

Funnels email into HipChat
Other
18 stars 2 forks source link

Possible security hole if no secret is provided #1

Open gabrielg opened 12 years ago

gabrielg commented 12 years ago

Someone can probably just give the md5 hash of the rest of the POST request as a signature, and have it be valid. Need to test/fix.