oren — 4/7/2022, 1:12:45 PM

This is a problem. Jeffalo will have to provide the private keys if you want to implement oauth

↩ repost
jeffalo — 4/7/2022, 8:01:43 AM

so for those of you making native wasteof clients, how does login work?

eg. how do you allow people to login via github/google?

♥ 16 ↩ 1 💬 4 comments
♥ 1 ↩ 0 💬 1 comment

comments

micahlt:

Do you mean the client secret? Yeah, you're right. I definitely wouldn't give someone else my client secret to an OAuth API. The more secure way would be to have some sort of page on wasteof.money that would allow you to authenticate with OAuth but then would open the mobile app and send the token with it.

4/8/2022, 1:50:05 PM