Andre Medeiros 428f591330
Don't send token in request body.
Instead, we want to hash a header to sign a request with a client nonce,
http method and URL. This is a first step towards protecting the backend
against eavesdropping.

Please note that this will still be susceptible to replay attacks.
2018-10-23 11:01:11 +02:00
..
2018-10-23 10:40:13 +02:00
2018-10-23 10:15:46 +02:00
2018-10-23 10:59:18 +02:00
2018-10-23 10:57:04 +02:00
2018-10-23 10:41:22 +02:00
2018-10-23 10:44:13 +02:00
2018-10-23 10:36:57 +02:00
2018-10-23 10:26:14 +02:00
2018-10-23 10:57:04 +02:00
2018-10-23 10:50:39 +02:00
2018-09-13 10:29:03 -04:00
2018-10-23 10:41:22 +02:00
2018-10-23 10:59:16 +02:00
2018-10-23 10:59:16 +02:00
2018-10-23 10:47:24 +02:00
2018-10-23 10:26:14 +02:00