You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
You asked to fill an issue if we think the Oauth2 app *client_secret is security risk in frontend.
Just to let you know that your client secret can be use to manipulate other GitHub resources using other mechanism than Oauth2 authorization_code flow.
They can be use in GitHub authorization APIs to gain informations about your end-user for example (https://developer.github.com/v3/oauth_authorizations/).
The text was updated successfully, but these errors were encountered:
I've been thinking about the same when reading about client_secret to be used on the front-end. After reading your ticket about it the thing that made it even more funnier that we even think alike with our profile pictures. 😆
Hello,
You asked to fill an issue if we think the Oauth2 app *client_secret is security risk in frontend.
Just to let you know that your client secret can be use to manipulate other GitHub resources using other mechanism than Oauth2 authorization_code flow.
They can be use in GitHub authorization APIs to gain informations about your end-user for example (https://developer.github.com/v3/oauth_authorizations/).
The text was updated successfully, but these errors were encountered: