romance-ii / violet-volts

violet-volts
https://tootsville.org/development/
GNU Affero General Public License v3.0
3 stars 1 forks source link

Switch from Google `tokeninfo` to local public-key verification #105

Open brpocock opened 7 years ago

brpocock commented 7 years ago

See https://developers.google.com/identity/sign-in/web/backend-auth for discussion

May be faster to verify using Ironclad on-host rather than relaying to Google, as well as potentially removing a MitM attack