|
|
|
|
|
by self_awareness
2070 days ago
|
|
Can it be used in desktop apps or mobile apps? I remember something that previous versions were for webapps only. Never used it though. Edit: What's wrong with you people? You're downvoting questions now? I remember that OAuth forced the user to include client secret in app's binary. When extracted, everyone could impersonate the app. If you don't understand the problem then don't downvote. |
|
> I remember something that previous versions were for webapps only.
> I remember that OAuth forced the user to include client secret in app's binary.
This is not actually a problem with RFC 7636.