Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Improve oauth security #9

Closed
ThiefMaster opened this issue Feb 22, 2021 · 0 comments · Fixed by #10
Closed

Improve oauth security #9

ThiefMaster opened this issue Feb 22, 2021 · 0 comments · Fixed by #10
Assignees

Comments

@ThiefMaster
Copy link
Member

Unless Indico 3.0 is released by the time we release this, we need to keep support for the old implicit flow (and confirm whether 2.3 supports the access token in a header) and only use the new one if the server is running on indico v3.

If we manage to improve this before the indico v3 release (and publish to both the iOS and Android app stores), the "Support implicit grant for the checkin app" commit in Indico should be be reverted as it won't be needed anymore.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging a pull request may close this issue.

2 participants