How About Tomorrow?
Open Source Security Theater
Dax
Okay, so the root thing is here, the access token is sent to random places. It's sent to APIs, it's sent to other people. The refresh token is never sent anywhere except to the authorization server. So that like moves, that flies around less. So it's theoretically, you know, less exposed. So we had that model.
0
💬
0
Comments
Log in to comment.
There are no comments yet.