tokens.Serializer: use encryption instead of plain signing
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 40
- Forks
- 4
- PR merge metrics
- No merged PRs in 30d
Description
itsdangerous only supports HMAC-style signing of payload data, but really it would be better to use proper encryption so that tokens.Serializer is usable on deployments which need PKCE et al (which would allow the Flask wrapper to return to a tokens.Serializer default).
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start by tracing the tokens.Serializer entry point and the Flask wrapper that currently depends on itsdangerous signing. Determine the encryption and PKCE compatibility requirements, then verify that the wrapper can use tokens.Serializer as its default without exposing payload data.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- flask, python
- Domain
- authentication
- Issue type
- Feature
- Difficulty
- 5/5
- Estimated time
- Over a week
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100