nitter
Logo
earlier replies
Dropbox API @dropboxapi
6 Jul 2022
Replying to @johnhess
Yes, the Dropbox "app key" is the "client ID" from the OAuth 2 spec, and is not considered secret. Here are several resources regarding OAuth 2 security and best practices that may be a helpful reference: datatracker.ietf.org/doc/htm… datatracker.ietf.org/doc/htm… oauth.com/oauth2-servers/aut…

Security Considerations - OAuth 2.0 Simplified

Below are some known issues that should be taken into consideration when building an authorization server. In addition to the considerations listed here,

oauth.com
1
1
Aaron Parecki @aaronpk
7 Jul 2022
Replying to @dropboxapi @johnhess
Yes! More info on this problem here: developer.okta.com/blog/2022…

The Identity of OAuth Public Clients

Should you be worried about OAuth client impersonation? Let's answer some of the most frequently misunderstood questions about

developer.okta.com

Jul 7, 2022 · 1:41 AM UTC

1