Answer the question
In order to leave comments, you need to log in
What is the danger of "client" oAuth authorization?
Social networks usually offer to log in through them in two ways:
1) Server. The user goes to the social network, from there he is transferred to our site with a certain key, then we use this key + our secret key to get a token.
2) Client. The user goes to the social network, from there he is transferred to our site with a hash token.
The second option usually comes with a footnote that it is unsafe.
It is always mandatory to use SSL.
What is the danger of the second approach? Who and how can intercept such a token?
And I also wonder why it is transmitted in hash? Why not a get parameter, for example?
Answer the question
In order to leave comments, you need to log in
us to the site with a hash token
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question