4 ms·
> Part of the problem is that it's just so opaque. You send the token and the server replies "nope", with no further explanation. Catch-all HTTP 401s and 403s
by xtajv 3y ago
> Part of the problem is that it's just so opaque. You send the token and the server replies "nope", with no further explanation.
Catch-all HTTP 401s and 403s are there to thwart https://en.wikipedia.org/wiki/Oracle_attack https://en.wikipedia.org/wiki/Oracle_attack - unfortunately, servers cannot afford to be "helpful" when it comes to unauthenticated clients.
- mmbop 3y agoThey should have a debug mode that is user-activated for stuff like this. I also have burned too many hours trying to get various OAuth flows working.
- magicalhippo 3y agoYeah some development servers that didn't actually send the mail anywhere but did give usable error messages for example would be amazing. To avoid it being used as an attack vector they could be tied to special app registrations that had to be registered with the mail development system in advance.