Harden hook #50

Closed
opened 2018-05-16 18:18:38 +02:00 by kauffj · 1 comment
kauffj commented 2018-05-16 18:18:38 +02:00 (Migrated from github.com)

Ensure we've done all we can to reduce abuse of the hook. Do we need to whitelist claim recipients? Require certain credentials? etc.

(And whitelist / restrict allowed calls to daemon.lbry.tech)

Ensure we've done all we can to reduce abuse of the hook. Do we need to whitelist claim recipients? Require certain credentials? etc. (And whitelist / restrict allowed calls to daemon.lbry.tech)
Krisseck commented 2018-05-23 16:23:50 +02:00 (Migrated from github.com)

The hook has now been hardened by whitelisting the allowed methods and wallet_send amounts and receivers. Only thing missing now is to have the daemon only accept connections from the site.

The hook has now been hardened by whitelisting the allowed methods and wallet_send amounts and receivers. Only thing missing now is to have the daemon only accept connections from the site.
Sign in to join this conversation.
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference: LBRYCommunity/lbry.tech#50
No description provided.