Oauth authorization without storing the secret key
Hey Guys,
Storing the Oauth secret key inside the app is not a secure solution, what is the alternative way to authorize without a need for that? I mean besides delegating the task toa server based Oath authorization. For example, Mendeley allows Oauth without a secret code.
Thanks
Storing the Oauth secret key inside the app is not a secure solution, what is the alternative way to authorize without a need for that? I mean besides delegating the task toa server based Oath authorization. For example, Mendeley allows Oauth without a secret code.
Thanks
-
dstillmanBetter to post this to zotero-dev. We try to keep technical discussions there.