Closed Keyrxng closed 2 weeks ago
@whilefoo @gentlementlegen rfc
Exposing the signature should not be a problem because you can't recover the private key from the signature
Got it, it seemed to me that if someone copied and pasted a signature from any plugin they'd be able to get that signature verified but I'm unclear on the exact specifics of things but thanks for clearing it up @whilefoo
It's my understanding that the signature has been returned as a means of authentication between kernel and plugins.
token
, so while it may be hacky we could rename this likekernel-access-token
or something and it'll be converted to****