mirror of
https://github.com/jech/galene.git
synced 2024-12-22 15:25:48 +01:00
03038eaf45
If the WHIP session is not authenticated, then the only thing preventing an attacker from DELETEing the session is the session URL. Since client ids are known, obfuscate the id before using it in the session URL. |
||
---|---|---|
.. | ||
webserver.go | ||
webserver_test.go | ||
whip.go |