You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The new version of this component requires shared apple password as input parameter to verify receipt. If someone reverse engineer the binary they can retrieve the password and use it for malicious purposes!!
the shared secret is supposed to be used on own server for verifying receipts
The text was updated successfully, but these errors were encountered:
This is done in the AppleReceiptValidator class, which is simply a reference implementation for how to do receipt validation with Apple.
Sounds like I should clarify this in the README so that users are aware of any security implications and quote any recommendations by Apple on this matter.
The new version of this component requires shared apple password as input parameter to verify receipt. If someone reverse engineer the binary they can retrieve the password and use it for malicious purposes!!
the shared secret is supposed to be used on own server for verifying receipts
The text was updated successfully, but these errors were encountered: