Comment 3 for bug 998185

Revision history for this message
Joseph Heck (heckj) wrote : Re: Once a token is created/distributed its expiry date can be circumvented

I'm not 100% clear on the original reason behind the token-based auth and chaining, or even if that was a requirement. Adding dolphm and termie to this email - they may have more visibility into the original design decisions.

My understanding of the original pattern was that the implementors were already familiar with a token-based authentication mechanism from rackspace and architected the initial token mechanism to match that pattern, potentially identically.