High security issue!
-
The JS for reloading directly calls the api. Which would be no problem if it would be public with no auth. But the client-id AND the oauth token are readable in js… its easily doable via network tab in any browser with pausing the code. just do a call to a local php file which calls the api then without users can read credentials
Viewing 1 replies (of 1 total)
Viewing 1 replies (of 1 total)
- The topic ‘High security issue!’ is closed to new replies.