top | item 46761704

(no title)

Mic92 | 1 month ago

I skipped over the first few ones and haven't seen critical ones. The hardcoded oauth client secrets is basically present in any open-source or commercial app that is distributed to end users. It doesn't break the security of end users. It mainly allows other apps to impersonate this app, i.e. present itself as clawdbot, which is a moot point given anyone can just change /inject code into it.

discuss

order

xtagon|1 month ago

Yeah, I see what you're saying.