Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Remove auto approve from api #45

Open
tiago18c opened this issue Sep 16, 2021 · 1 comment
Open

Remove auto approve from api #45

tiago18c opened this issue Sep 16, 2021 · 1 comment

Comments

@tiago18c
Copy link

API consumers shouldn't have access to this knowledge, this should be strictly on the wallet side.

Why? Today I was investigation a couple of phishing websites, and both of them check if the user has auto approved or not.
Both were acting differently, but both were abusing this information.

@tiago18c
Copy link
Author

More context: anza-xyz/wallet-adapter#82

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant