-
-
Notifications
You must be signed in to change notification settings - Fork 120
Open
Labels
A-Client-ServerIssues affecting the CS APIIssues affecting the CS APIfeatureSuggestion for a significant extension which needs considerable considerationSuggestion for a significant extension which needs considerable consideration
Description
moving access_tokens to the http headers mitigated it, but it's still quite easy to leak an access_token, in which case, you lose. Perhaps we should consider using something like OAuth 1 signatures, like twitter: https://developer.twitter.com/en/docs/basics/authentication/guides/creating-a-signature
ptman
Metadata
Metadata
Assignees
Labels
A-Client-ServerIssues affecting the CS APIIssues affecting the CS APIfeatureSuggestion for a significant extension which needs considerable considerationSuggestion for a significant extension which needs considerable consideration