|
|
|
|
|
by dawkins
4479 days ago
|
|
Even if your api uses oAuth I don't see how can you prevent the client app to steal the password.
At some point the user is going to have to give his password to someone. Can't the app ask the user for his password, keep it, and internally give it to oAuth to allow to use your api? |
|