💼 BusKill (laptop kill-cords)
cybersecurity @infosec.pub Why OAuth MUST share access token with 3rd party?!?
Linux @programming.dev PSA: Upgrade your LUKS PBKDF to Argon2id !!
Linux @sopuli.xyz PSA: Upgrade your LUKS PBKDF to Argon2id!
Linux @discuss.tchncs.de PSA: Upgrade your LUKS PBKDF to Argon2id!
Linux @sh.itjust.works PSA: Upgrade your LUKS PBKDF to Argon2id !!
I figured it out. It's because Stripe doesn't allow the redirect during the OAuth flow to be dynamic. It must be a predefined value that's hard-coded into the app.
That's why Stripe forces you to expose your access tokens to the developer's servers.
I'd still appreciate if someone with more experience with OAuth than me knows if this is common. Seems like a very bad design decision to require users to transmit their bearer tokens through the developer's servers.