Has anyone tried a password auth system that standardizes on some front-end hashing strategy, so that the API never sees/touches the plain text version of the password?
3
1
9
It's part of the old-school HTTP Digest Auth en.wikipedia.org/wiki/Digest⦠It just doesn't really solve things the way you'd expect.
Dec 11, 2020 Β· 3:57 PM UTC
1

