Recherches récentes
Pas de recherche récente

Sarah
Adhésion le 15 janv. 2025
·
Dernière activité le 15 janv. 2025
Suivis
0
Abonnés
0
Activité totale
1
Votes
0
Abonnements
0
APERÇU DES ACTIVITÉS
BADGES
ARTICLES
PUBLICATIONS
COMMENTAIRES DE LA COMMUNAUTÉ
COMMENTAIRES SUR L’ARTICLE
APERÇU DES ACTIVITÉS
Dernière activité effectuée par Sarah
Sarah a créé une publication,
Dear Zendesk Team,
We would like to address the recent decision to disable the implicit grant flow for OAuth. While we understand the intent to improve security, this change does not align with our practical use case and introduces significant challenges.
Key Points:
-
No Real Security Improvement:
- The implicit flow is not inherently less secure than the authorization code flow in our controlled environment.
- Since the access token is processed within our controller, it is still exposed to browser extensions or malicious scripts in both scenarios.
-
Huge Disadvantage for Us and Our Customers:
- Switching to the authorization code flow would require all our customers to update their business program that we deliver.
- Many customers are unlikely to update just to support new Zendesk integrations for new users, especially for such a small functionality.
Our Request:
We kindly request Zendesk to reconsider disabling the implicit grant flow or provide an opt-in option for customers where this change imposes significant operational and practical challenges.
Thank you for your understanding and consideration.
Publication le 15 janv. 2025 · Sarah
0
Abonnés
2
Votes
1
Commentaire