You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
While LTI launches are validated against the consumer key/secret pair stored internally, the LTI spec indicates that only requests coming from the corresponding domain. This prevents pirated secret/key pairs from being used without also deploying some kind of DNS/routing/spoofing attack. CodeWorkout currently does not check the domain where requests originate to implement this protection.
The text was updated successfully, but these errors were encountered:
While LTI launches are validated against the consumer key/secret pair stored internally, the LTI spec indicates that only requests coming from the corresponding domain. This prevents pirated secret/key pairs from being used without also deploying some kind of DNS/routing/spoofing attack. CodeWorkout currently does not check the domain where requests originate to implement this protection.
The text was updated successfully, but these errors were encountered: