Replies: 2 comments
-
个人看法 以上 |
Beta Was this translation helpful? Give feedback.
0 replies
-
@Pai2Chen 反向websocket也可以,我也只是想提出一个新的想法,大家来研究研究可行性 |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
当前版本(v11)的OneBot对于鉴权只提供了Access Token鉴权方法,安全程度并不理想,也不方便多人共用一个Bot情景下的授权管理。
我认为bot端的鉴权可以补充一个密钥对鉴权(SecretID&SecretKey),请求api时传递SecretID和以SecretKey为密钥,对Body(或者指定一些Header的值)进行HMAC-SHA1计算的结果。
以上。
Beta Was this translation helpful? Give feedback.
All reactions