Hacker News new | ask | show | jobs
by tiarafawn 1018 days ago
This problem/attack is called "confused deputy". It's surprisingly hard to find a link that correctly explains the problem and its mitigations. This one is correct but not very verbose: https://medium.com/@fhbro/confused-deputy-c9e75eb7df00#8edf