all repos — honk @ f2810582a82e8f29b1f9222d629b4001e5f1d8d2

my fork of honk

trustno1
Ted Unangst tedu@tedunangst.com
Sun, 14 Apr 2019 14:17:50 -0400
commit

f2810582a82e8f29b1f9222d629b4001e5f1d8d2

parent

5c2d16d5da8485c7370bea029947fbcfa40552f5

1 files changed, 4 insertions(+), 0 deletions(-)

jump to
M docs/security.txtdocs/security.txt

@@ -5,6 +5,10 @@ honk is not currently hardened against SSRF, server side request forgery. Be

mindful of what else may be reachable on localhost or the local network if it's not generally accessible. +Key and signature verification is best effort, but some forgeries may sneak +past. In particular, tying together key name, key owner, actor, object, etc. +is incomplete. + How are user keys supposed to be rotated? Expired? Revoked? The current answer is never, never, never.