Lock access_token to IP address #20

Open
opened 2025-07-03 15:14:17 +00:00 by radical · 0 comments
Owner

Return a 403 when access token is used from another IP than the one that created it, will lead to no functional change for users but will prevent token theft by eventual plugins that may exist for the frontend or 3rd party clients

Return a 403 when access token is used from another IP than the one that created it, will lead to no functional change for users but will prevent token theft by eventual plugins that may exist for the frontend or 3rd party clients
radical added the
Kind/Enhancement
Reviewed
Confirmed
Priority
Medium
labels 2025-07-23 14:07:59 +00:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: gorb/backend#20
No description provided.