标签:#hack
找到 10514 篇相关文章
Google's New reCAPTCHA Wants Your Camera Access and 21 Points of Your Hand
Magicbookshelf.org – a spoiler-aware companion for public domain classics
Can Printed 'Skin' Heal Burns and Prevent Scars?
Perform DFU Restores on Apple Silicon Macs with Macvdmtool (2021)
Suffocating mega heat dome to engulf 35 states as forecasters issue urgent alert
Open-sourcing Revolut's talent system: How we built Europe's top tech company
Segmenting Robot Video into Actionable Subtasks
A.I. 'Employees' Might Disrupt Work in Unexpected Ways
.self: A new top-level domain designed to support self-hosting
The Richest Country Is Pretty Mid Now [Benn Jordan][video]
Asymmetric Quantization: Near-Lossless Retrieval with 97% Storage Reduction
Microsoft worker emails colleagues about company's support for genocidal Israel
Why narcissistic leaders resist remote work
JumpServer: Open-Source Privileged Access Management
wolfSSL vs. MbedTLS
CERN bids farewell to the LHC and enters Long Shutdown 3
.garden TLD's change to a bad neighborhood
Feds Tracked Down an Anti-ICE Dad in NYC Hotel, but How?
Making Human Approvals Trustworthy
At first, approvals sound simple. Show a button. Let someone click approve. Continue the workflow. But real approvals are much harder than that. Nod has to answer important questions: Who requested this approval? Who approved or rejected it? Was the person allowed to decide? Did the approval expire? Was the callback delivered? Can we prove what happened later? That is why Nod stores approvals as real state, not temporary UI. Each approval has a status: pending approved rejected expired canceled Only one final decision can win. If two people click at the same time, Nod must safely accept the first valid decision and reject stale attempts. Slack also needs careful handling. Nod verifies Slack signatures, checks the approval and channel, and stores an actor snapshot for the audit log. After a decision, Slack messages can be updated so old buttons are no longer useful. Webhooks also need trust. Nod signs every callback so customer apps can verify it before continuing. const event = nod . webhooks . verify ({ rawBody , headers : request . headers , secret : process . env . NOD_WEBHOOK_SECRET ! , }); We learned that approvals are not just a product feature. They are a security system. A good approval layer needs: Authorization Idempotency Expiration Webhook signing Retry logic Audit logs That is what Nod is built around.