|
|
|
|
|
by 1337badger
4292 days ago
|
|
From what I gather you are leaving the api_tokens for the services in local memory. This means that the user or anyone else that can get there hands on the token can act on the service providers api masquerading as your application. |
|