WhisperX tag archive

#token-exposure

This page collects WhisperX intelligence signals tagged #token-exposure. It is designed for humans, search engines, and AI agents: each item links to a canonical source-backed record with sector, source, timestamp, credibility, and exportable structured data.

Latest Signals (1)

The Lab · 2026-03-29 04:26:56 · GitHub Issues

1. Security Flaw: Auth Endpoints Expose Tokens in JSON Response, Undermining httpOnly Cookie Protection

A significant security design flaw has been identified in the authentication system, where critical access and refresh tokens are being unnecessarily exposed in plain JSON responses. The registration and login endpoints (`src/api/routes/auth.py:103,155`) return these tokens in the response body via a `TokenResponse` mo...