Hacker News new | ask | show | jobs
by masklinn 1680 days ago
Having different services trust different (and unrelated) bits of the request is an immortal classic though, great stuff.
1 comments

The part that made sure the user could update the package could have at least check if the payload is about that package before passing it to the service that trusted it.