Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

密码存储在客户端不安全 #12

Open
wangjia2016 opened this issue Apr 13, 2020 · 3 comments
Open

密码存储在客户端不安全 #12

wangjia2016 opened this issue Apr 13, 2020 · 3 comments

Comments

@wangjia2016
Copy link

密码存储在客户端不安全

@CANGWU
Copy link
Collaborator

CANGWU commented Apr 14, 2020

哪部分密码,是指客户端的密码吗

@wangjia2016
Copy link
Author

哪部分密码,是指客户端的密码吗

是的,oauth 的客户端密码

@CANGWU
Copy link
Collaborator

CANGWU commented Apr 15, 2020

如果客户端直接是浏览器之类的,那确实容易泄露客户端的密钥。但是如果客户端也是服务器,比如提供nodejs层,在nodejs服务器中保存客户端的密钥信息,安全性会有所提高,这个关键看客户端的实现方式,因为这些确实是属于客户端持有的的信息。在不允许客户端授权模式的情况下,就算泄漏的客户端密码影响不大,因为还需要用户的授权才能获取到token

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants