Google OAuth - Keeping the Client ID Secret

不打扰是莪最后的温柔 提交于 2019-12-04 07:36:53
willlma

You don't. Anyone can see and intercept it (as you stated), which is the root of the confused deputy problem.

That's why you validate your tokens. For a simple explanation of token validation and the confused deputy problem, check out this great SO question and answer on How and why is Google OAuth token validation performed.

易学教程内所有资源均来自网络或用户发布的内容,如有违反法律规定的内容欢迎反馈
该文章没有解决你所遇到的问题?点击提问,说说你的问题,让更多的人一起探讨吧!