3 ms·
I did, once. But after that one entirely new sessions, they automatically "click" the sign in to google button behind the scenes and log me in with the token.
by vtesucks 8y ago
I did, once. But after that one entirely new sessions, they automatically "click" the sign in to google button behind the scenes and log me in with the token.
Very creepy
- AYBABTME 8y agoI don't like Quora, but... that's just how OAuth is meant to work.
- ceejayoz 8y agoI will say I appreciate Facebook's approach to this - after 60-90 days, you have to affirmatively reconfirm your initial authorization when they send you through the OAuth flow.
- Crosseye_Jack 8y agoRevoke the auth with google and clear any cookies you have with Quora. Worse that will happen if they redirect you to google to login.
- caseysoftware 8y agoThe first time you logged in with Google, you were presented with a User Consent screen that said "this website wants access to this information, do you agree?" and you clicked yes. To break the link, go into Google and see what sites, apps, etc you granted access to. That's a good thing to do regularly anyway with every social provider. I wrote about the implications of poorly implemented and abusive social authentication practices last month: https://www.scmagazine.com/home/security-news/using-social-auth-with-your-app-4-steps-to-protect-your-users-and-mitigate-security-concerns/ https://www.scmagazine.com/home/security-news/using-social-a...
- wallnuss 8y agoYou can revoke OAuth tokens at https://accounts.google.com/b/0/IssuedAuthSubTokens?hl=en https://accounts.google.com/b/0/IssuedAuthSubTokens?hl=en