"+" bug in mac_key?

Wechsler wechsler at phase.org
Tue Aug 2 14:55:28 PDT 2005


Brad Fitzpatrick wrote:
> All that comes to mind is that somebody escaping/descaping the parameter
> as a URL parameter one too many/few times.
> 

AFAICT the mac_key never passes through a URL, as far as I can see - 
it's recovered from a key:value set in the body of an HTTP response.


More information about the yadis mailing list