4 ms·
Can someone explain to me why the access code is sent back as the hash in the url not the query string?
by snikch 14y ago
Can someone explain to me why the access code is sent back as the hash in the url not the query string?
- homakov 14y agobecause query string is available in document.referrer on external websites. hash is supposed to be more secure - not sent on server side. but with 302 redirects it's not so secure.
- bsimpson 14y agoBut this is only for JavaScript clients, right? I believe all the OAuth APIs I've consumed from Python send access_token in the query string.
- homakov 14y agowhat provider? Facebook never sends it in query string. It can also be available for Man In The Middle, in server side logs etc. Hash is supposed to be more secure.
- johns 14y agoFB definitely sends access token via URL param for the server side flow: https://developers.facebook.com/docs/howtos/login/server-side-login/ https://developers.facebook.com/docs/howtos/login/server-sid... If there were a mitm they could get it even if it's in the hash. It has to travel to the client at some point.
- homakov 14y agoif it's in hash it can be seen only from FB response (https). redirect_uri can be http so hash is not transferred of course it's visible in server-2-server, but not client-server
- jkrems 14y agoMaybe you are thinking of the code parameter? The one that can be exchanged for an access token in a server-to-server request?
- bsimpson 14y agoI believe they're both in the query string, but you're right - code is what's sent by way of the client. access_token is exchanged between the servers.