3 ms·
I believe your concern is a valid one, end-points of single page apps should respect authorization requirements, and assume the client is always compromised. U
by iamstef 12y ago
I believe your concern is a valid one, end-points of single page apps should respect authorization requirements, and assume the client is always compromised.
Unfortunately, I believe you may have missed the point of this library and blog post. It merely simplifies the developers life when implementing the client side flows and interactions associated with authorization with one or more auth providers.
This does not preclude proper API authorization or loading sensitive modules post authorization from an authorized end-point.
As someone who has implement many very related flows, I am glad to see an effort to unify, share and simplify this experience.