Live data from Hacker News

ItsDangerous

itsdangerous.palletsprojects.com

31–34 of 34 posts

Re: ItsDangerous

#31

Earlier quoted context omitted.

Nowhere in the HN guidelines[1] is it required (or even recommended) for a submission to be new or even recent - there are popular submissions going back to the 1900's and others that have hit the front page a dozen times because they're timeless or little-known. The fact that the submission has 73 upvotes (as of this comment) and that I found it novel and interesting suggests that it's rather on-topic, and interesti…

you sound so arrogant and mad lol

Please don't do this here.

Re: ItsDangerous

#32
post #10

Earlier quoted context omitted.

JWT specified all the crypto algorithms; even future ones. They did not intend people to accept more then a very small subset. This was insufficiently well communicated.

Where? RFC 7519 states pretty specifically that only HMAC SHA-256 "none" MUST be implemented. The rest were left up to devs as optional.

I don't think it means what you're suggesting, but maybe I'm misunderstanding you. The previous paragraph in the RFC says:

> Applications using this specification can impose additional requirements upon implementations that they use. For instance, one application might require support for encrypted JWTs and Nested JWTs, while another might require support for signing JWTs with the Elliptic Curve Digital Signature Algorithm (ECDSA) using the P-256 curve and the SHA-256 hash algorithm ("ES256").

In the next paragraph it says:

> Of the signature and MAC algorithms specified in JSON Web Algorithms [JWA], only HMAC SHA-256 ("HS256") and "none" MUST be implemented by conforming JWT implementations.

They're making the distinction here between JWT implementations (i.e. libraries) and applications that use JWT. Nothing mandates that applications must accept the "none" method. The earlier paragraph gives specific usage examples in which a small subset of options are allowed by the application. That is the intended use.

In this later paragraph they're just establishing a baseline of encryption support in libraries; i.e., what is the minimal set of choices that a library can offer to an application. Applications are still expected to actually choose.

Re: ItsDangerous

#33

Earlier quoted context omitted.

What did you hear about it?

They were asking what it was for. I suspect the person reviewing the list had no idea what they were doing. If there's going to be security threat lurking in there its not going to be in the package named "itsdangerous", its going to in the one with a typo in the name.

on the other hand, just on the off chance that it is malware, you really don't want to be the guy who didn't ask about the package called "itsdangerous"

Re: ItsDangerous

#34
post #30

Earlier quoted context omitted.

Nowhere in the HN guidelines[1] is it required (or even recommended) for a submission to be new or even recent - there are popular submissions going back to the 1900's and others that have hit the front page a dozen times because they're timeless or little-known. The fact that the submission has 73 upvotes (as of this comment) and that I found it novel and interesting suggests that it's rather on-topic, and interesti…

Please edit swipes like that last bit out of your comments here. Your other points are fine. https://news.ycombinator.com/newsguidelines.html

My apologies. You have my permission to edit it - I'm past my edit window now.
Post reply on HN