最近搜索
没有最近搜索

Sarah
已加入2025年1月15日
·
最后活动2025年1月15日
关注
0
关注者
0
活动总数
1
投票
0
订阅
0
活动概览
标记
文章
帖子
社区评论
文章评论
活动概览
的最新活动 Sarah
Sarah 创建了一个帖子,
帖子 Feedback - Ticketing system (Support)
Dear Zendesk Team,
We would like to address the recent decision to disable the implicit grant flow for OAuth. While we understand the intent to improve security, this change does not align with our practical use case and introduces significant challenges.
Key Points:
-
No Real Security Improvement:
- The implicit flow is not inherently less secure than the authorization code flow in our controlled environment.
- Since the access token is processed within our controller, it is still exposed to browser extensions or malicious scripts in both scenarios.
-
Huge Disadvantage for Us and Our Customers:
- Switching to the authorization code flow would require all our customers to update their business program that we deliver.
- Many customers are unlikely to update just to support new Zendesk integrations for new users, especially for such a small functionality.
Our Request:
We kindly request Zendesk to reconsider disabling the implicit grant flow or provide an opt-in option for customers where this change imposes significant operational and practical challenges.
Thank you for your understanding and consideration.
已于 2025年1月15日 发布 · Sarah
0
关注者
2
投票
1
Comment