access_token and refresh_token forwarded through developer website... #526

Open
Grimeton opened this Issue Feb 7, 2017 · 0 comments

Comments

Projects
None yet
2 participants

Grimeton commented Feb 7, 2017

Hello,

it should be CLEARLY MENTIONED IN THE README AND THE OTHER DOCS THAT USING THE OAUTH METHOD WITHOUT YOUR OWN SECURITY PROFILE FORWARDS THE auth_token AND THE refresh_token VIA THE DEVELOPERS WEBSITE EACH HOUR. THIS OPENS A DOOR FOR PEOPLE HAVING ACCESS TO THE SERVER TO ACCESS YOUR CLOUD DRIVE AND ALL YOUR DATA.

https://github.com/yadayada/acd_cli/blob/master/acdcli/api/oauth.py line 192 and following.

I personally don't like it but If people want to go with that option they should be CLEARLY WARNED that this is the case. Independent of what source code is shown to be running on the website.

Cu

yadayada added the duplicate label Mar 5, 2017

@yadayada yadayada added a commit that referenced this issue Mar 5, 2017

@yadayada yadayada expand authentication doc
Adds warning about forwarding OAuth data (closes #404, #526),
infos about copying credentials, using multiple accounts (#538).
1921248
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment