lundi 11 mai 2020

Sending extra string in client secret does break the oauth standord

I have a requirement to handle the /token end point request with extra string. We are planning to send the extra String by appending with client secret and separate the extra String in a custom authorizer. My question is if we are using client secret by appending multiple String to solve our problem, does it break the Oauth protocol . Need expert opinion on this.

Aucun commentaire:

Enregistrer un commentaire