Hacker News new | ask | show | jobs
by baz00 1021 days ago
Leaving credentials and keys in memory.
1 comments

Also completely failing to check the scope of the request before validating it!

> Microsoft provided an API to help validate the signatures cryptographically but did not update these libraries to perform this scope validation automatically