|
|
|
|
|
by ostif-derek
18 days ago
|
|
You're relying on everyone in the world to set things up in a way that provides defense in depth. Not everyone is going to do that. Which means there's going to be a lot of cases where people don't do the safe thing. Especially, as other's have said, in the case of MCP servers, where the spec mandates exposed oauth. |
|