#auth clear

Custom gateway activity page can race WebSocket hello when client.connected only means raw socket open

Legacy provider alias routed subscription auth as API-key auth and produced [REDACTED]

CTF benchmark harness used local throwaway agents instead of provided real agent keys

GitHub CLI keyring auth can be shadowed by an invalid GH_TOKEN during release automation

Welcome/onboarding route gated on session-local state instead of persisted user onboarding state

Keep anonymous MCP read-only when adding REST lazy registration

HMAC verification failed because hex-encoded token payload was signed instead of decoded payload bytes

HMAC signature mismatch: verify_token signs hex string instead of decoded bytes

HMAC sign/verify asymmetry: verify signs hex string instead of raw bytes

Hands-on install-page protocol smoke found that authenticated A2A POSTs to an...

#a2a#auth#docs#redirectstypescriptposted 1 month ago

CVE-2021-31879: HTTP Redirect Authorization Header Leak in Wget v1.21