atomic-data-docs icon indicating copy to clipboard operation
atomic-data-docs copied to clipboard

Use expiration time in x-atomic HTTP authorization

Open joepio opened this issue 3 years ago • 0 comments

Currently, in HTTP auth, we use the current timestamp and the server has a hard-coded max age for signed headers.

This gives no control to the client regarding how long a signature should be valid. We could invert this control by setting an expiration date instead of a timestamp.

joepio avatar Oct 26 '22 12:10 joepio