Skip to content

Passing OAuth Client ID directly to react-google-login will expose our credentials #181

Discussion options

You must be logged in to vote

@AminRafaey indeed, you'll want to use a different OAuth 2.0 grant type for browser-based applications, commonly recommended now is the PKCE flow.

But this isn't an npm issue, so shouldn't be here on the npm RFCs discussion board. You can likely find more answers on stackoverflow.

Replies: 2 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by darcyclarke
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
3 participants