PlaidWeb / PlaidWeb/Authl

tokens.Serializer: use encryption instead of plain signing

Open
#98 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
40
Forks
4
PR merge metrics
No merged PRs in 30d

Description

itsdangerous only supports HMAC-style signing of payload data, but really it would be better to use proper encryption so that tokens.Serializer is usable on deployments which need PKCE et al (which would allow the Flask wrapper to return to a tokens.Serializer default).

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by tracing the tokens.Serializer entry point and the Flask wrapper that currently depends on itsdangerous signing. Determine the encryption and PKCE compatibility requirements, then verify that the wrapper can use tokens.Serializer as its default without exposing payload data.

Written by the indexing model from the issue text.

Assessment

Tech stack
flask, python
Domain
authentication
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.