Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Couldn't agree more. I don't have the time right now to commit to another project, but I always love picking off a quick task if it's helpful.

As proof, GitPals posted[0] their own project on GitPals. The sole comment mentions that they're looking for help auditing their JWT implementation. This is a sufficiently small and well-scoped task, and so I did[1]! I admittedly opened GitPals with no expectation of contributing, but the ask was small enough that it seemed reasonable.

[0] https://www.gitpals.com/projects/GitPals

[1] https://github.com/danmoop/GitPals/issues/8



I don't understand why this site even needs a JWT. Couldn't they just use a typical cookie-based login flow?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: