-
Notifications
You must be signed in to change notification settings - Fork 274
feat(appcheck): Verify one-time tokens for replay protection #774
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
yvonnep165
wants to merge
20
commits into
dev
Choose a base branch
from
yp-verify-one-time-token
base: dev
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
+167
−15
Open
Changes from 17 commits
Commits
Show all changes
20 commits
Select commit
Hold shift + click to select a range
ed9b1fb
Add replay protection feature
agbaraka b8487ba
refactor code and description
agbaraka 6c999a4
refactor code and cleanup as per feedback
agbaraka 604af8d
Refactor token verifier URL generation
agbaraka c746ccb
Merge branch 'dev' into feature/app-check-consume-endpoint
agbaraka 97e1f4d
Refactor code and cleanup
agbaraka 3946367
Revert package updates
agbaraka 863183a
Fix linter errors
agbaraka 7064317
Fix failed tests
agbaraka 688d513
Refactor to include http failures test cases
agbaraka b09857b
Add one time token verification support
yvonnep165 d580ec0
Add unit tests
yvonnep165 8acd3c3
Fix formatting
yvonnep165 0efa019
Use a helper function boolPtr in tests
yvonnep165 99b64d1
Restore original value of verifyURLFormat using defer
yvonnep165 f1bbce2
Fix unit test error
yvonnep165 6d3c8b2
Merge PR #641 for credit attribution
yvonnep165 9de05fb
Update to v1 endpoint
yvonnep165 a357931
update the JWKSUrl to remove beta
yvonnep165 ee86e00
Merge branch 'dev' into yp-verify-one-time-token
yvonnep165 File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Our
v1endpoint is almost ready, and that would be our preferred URL when this SDK is released. Maybe we can just change this tov1now?I'm also fine with leaving this alone for now and wait until our
v1endpoint is fully published. In that case, is a TODO appropriate here?Uh oh!
There was an error while loading. Please reload this page.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks for the quick review! Sure, we can switch to the
v1endpoint as long as we can verify and run our tests against it. Currently, we only have unit tests in place so we can just change tov1now, but we plan to add integration tests against the live endpoint once we implement the token creation methods.There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
One thing we should keep in mind if we do merge this as v1, is that our next release will include this whether or not the backend is ready. Lets set v1 but hold back merging until the backend is live.