Hacker News new | ask | show | jobs
by svens_ 3476 days ago
It doesn't seem too bad when enforcing https (using the return address whitelisting in the developer console). Am I missing something?
1 comments

Customer will see token anyway
Ah yes, of course. I did miss that. The implicit (client-side) auth flow gets the access token directly and doesn't need another request to the API, that's the whole point.

This is indeed rather unwanted, even more so with the new more restrictive API usage policy and the sandbox.