Skip to content

mint_token lacks encryption/auth and is forgeable #2334

@cyberspace61

Description

@cyberspace61

Hi team,

I noticed that the current mint_token implementation is unencrypted and unauthenticated. This makes the tokens easily forgeable by attackers and exposes client IPs in plaintext.

Due to these security risks, this feature essentially cannot be enabled in real-world production environments (such as Cloudflare's own live websites).

Could you share your considerations regarding this design? Are there plans to provide a secure, production-ready implementation in the future?

Thanks!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions