Prevent crappy coders from leaking private keys.
if ($magicsig instanceof Magicsig) {
$xrd->links[] = new XML_XRD_Element_Link(Magicsig::PUBLICKEYREL,
- 'data:application/magic-public-key,'. $magicsig->toString(false));
+ 'data:application/magic-public-key,'. $magicsig->toString());
}
// TODO - finalize where the redirect should go on the publisher
/**
* Encode the keypair or public key as a string.
*
- * @param boolean $full_pair set to false to leave out the private key.
+ * @param boolean $full_pair set to true to include the private key.
* @return string
*/
- public function toString($full_pair = true)
+ public function toString($full_pair=false)
{
$mod = Magicsig::base64_url_encode($this->publicKey->modulus->toBytes());
$exp = Magicsig::base64_url_encode($this->publicKey->exponent->toBytes());