Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

You shouldn't. Simply check that the hash algorithm specified by the client is the one you used when issuing the token. In a side project, I simply hard code the algorithm [1].

[1]: https://github.com/teotwaki/grace-calendar/blob/develop/app/...

Edit: DYAC.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: