access_token and refresh_token forwarded through developer website... #526
Comments
yadayada
added the
documentation
label
Feb 11, 2017
yadayada
added the
duplicate
label
Mar 5, 2017
yadayada
added a commit
that referenced
this issue
Mar 5, 2017
|
|
yadayada |
1921248
|
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Grimeton commentedFeb 7, 2017
Hello,
it should be CLEARLY MENTIONED IN THE README AND THE OTHER DOCS THAT USING THE OAUTH METHOD WITHOUT YOUR OWN SECURITY PROFILE FORWARDS THE auth_token AND THE refresh_token VIA THE DEVELOPERS WEBSITE EACH HOUR. THIS OPENS A DOOR FOR PEOPLE HAVING ACCESS TO THE SERVER TO ACCESS YOUR CLOUD DRIVE AND ALL YOUR DATA.
https://github.com/yadayada/acd_cli/blob/master/acdcli/api/oauth.py line 192 and following.
I personally don't like it but If people want to go with that option they should be CLEARLY WARNED that this is the case. Independent of what source code is shown to be running on the website.
Cu