Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
OAuth and Single Page JavaScript Web-Apps (alexbilbie.com)
16 points by Inversechi on Dec 8, 2014 | hide | past | favorite | 1 comment


I'm confused: what exactly is the problem here?

Google APIs are designed [1] to be accessed on behalf of a Google account holder by client-side code without any server component being involved. The client-side code does not use client_secret, only client_id. There isn't any secret key to steal from the code.

[1] https://developers.google.com/accounts/docs/OAuth2UserAgent




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: