Hacker News
new
past
comments
ask
show
jobs
points
by
sergiotapia
5 hours ago
|
comments
by
carstonh
5 hours ago
|
[-]
agreed… why can an ID token for a separate client application be used to read and write to GitHub? that’s the story here.
reply
by
jsiepkes
3 hours ago
|
parent
|
[-]
Not checking the "audience" of a token or misconfiguring it is pretty common. A lot of applications don't actually check it.
reply