Key: permit empty keys only with ::empty() factory method#833
Merged
Ocramius merged 2 commits intolcobucci:4.2.xfrom Apr 7, 2022
Merged
Key: permit empty keys only with ::empty() factory method#833Ocramius merged 2 commits intolcobucci:4.2.xfrom
::empty() factory method#833Ocramius merged 2 commits intolcobucci:4.2.xfrom
Conversation
Collaborator
|
I'd still label it as BC break, but better to have a broken system, than a compromised one. No need for CVE/security issue, since this is mis-configuration on the consumer side, if it happens: instructions on using safe randomly generated keys were already provided. |
Ocramius
requested changes
Apr 7, 2022
::empty() factory method
Ocramius
reviewed
Apr 7, 2022
Owner
|
IHMO we shouldn't use the baseline to ignore errors we will never fix. That's why we have the annotations to ignore things. |
Collaborator
We should probably remove the exception, at some point, and only leave the types |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
I consider this a security bug that should be addressed with urgent.
Before this PR, misconfigurations can easily lead to unsecured token issuance under the radar, expecially where creator = consumer.