-
Notifications
You must be signed in to change notification settings - Fork 25.1k
Closed
Labels
⌚ Not TriagedSource - Docs.msDocs Customer feedback via GitHub IssueDocs Customer feedback via GitHub Issueaspnet-core/svcsecurity/subsvc
Description
Description
Content:
You should NOT create an access token from a username/password request. Username/password requests aren't authenticated and are vunerable to impersonation and phishing attacks. Access tokens should only be created using an OpenID Connect flow or an OAuth standard flow. Deviating from these standards can result in an insecure app.
Page URL
Content source URL
Document ID
8d24839c-6c0a-3b29-d9f1-0f52becbf0f5
Article author
Metadata
- ID: 8d24839c-6c0a-3b29-d9f1-0f52becbf0f5
- Service: aspnet-core
- Sub-service: security
Metadata
Metadata
Assignees
Labels
⌚ Not TriagedSource - Docs.msDocs Customer feedback via GitHub IssueDocs Customer feedback via GitHub Issueaspnet-core/svcsecurity/subsvc