|
|
|
|
|
by brianfletcher
1685 days ago
|
|
If you use the setup url callback, you don't get any authorization code just an installation id and the setup action. So there is no means to verify that the user honestly owns the installation that they are providing. Because the number is so short, it's easy to guess every combination. |
|