• 0 Posts
  • 5 Comments
Joined 2 years ago
cake
Cake day: June 12th, 2023

help-circle




  • trakata@lemmy.catoFediverse@lemmy.worldApp to schedule posts on Lemmy
    link
    fedilink
    English
    arrow-up
    4
    arrow-down
    1
    ·
    1 year ago

    I don’t store your password if that’s what you’re asking! …

    The JWT token is not stored on the server, it’s only in a cookie in your browser.

    When you schedule a post, the post details, your instance, your username and your JWT token are stored in a job…

    You’re simply storing secrets on the server and running it by proxy, nothing prevents you from extracting those JWTs from the job stores and actioning them against an arbitrary Lemmy API with crafted calls.