Skip to content

Navigation Menu

Sign in
Appearance settings

Search code, repositories, users, issues, pull requests...

Provide feedback

We read every piece of feedback, and take your input very seriously.

Saved searches

Use saved searches to filter your results more quickly

Appearance settings

Shouldn't you be using Safari instead of a web view? #11

Copy link
Copy link
@malhal

Description

@malhal
Issue body actions

I'm new to Oauth and was just wondering that if you are using a web view and if the user logs in then the app can just inject some javascript to monitor whats entered in the login page. Thus defeating the purpose of using Oauth. To prevent this shouldn't you open the URL in safari, have the user log in there, and then redirect back to the app afterwards? That way the app can't steal the users credentials. This is more of an issue for framework developers I suppose. However if this is designed for use in a highly trusted environment why not just use the password flow instead of authorisation code flow?

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions

      Morty Proxy This is a proxified and sanitized view of the page, visit original site.