diff --git a/http-signature-normalization-actix/src/lib.rs b/http-signature-normalization-actix/src/lib.rs index d3881ce..400c35d 100644 --- a/http-signature-normalization-actix/src/lib.rs +++ b/http-signature-normalization-actix/src/lib.rs @@ -345,6 +345,9 @@ impl Config { /// Opt out of using the (created) and (expires) fields introduced in draft 11 /// /// Use this for compatibility with mastodon + /// + /// Note that by enabling this, the Date header becomes required on requests. This is to + /// prevent replay attacks pub fn dont_use_created_field(self) -> Self { Config { config: self.config.dont_use_created_field(),