Hacker Newsnew | past | comments | ask | show | jobs | submit | adumbledore's commentslogin

How political was this decision? Seems like they wanted to get rid of him and citet some minor misdemeanor some time back.


It even says so on the official website ( https://oauth.net/2/grant-types/implicit/ ) - astonishing that they can't get this right. Maybe says something about the product?


Yep. I'm fairly concerned about an identity management company publishing this information.


Author here -

Entirely agree and we recommend using Auth Code+PKCE whenever possible. This post is intended to be the first of a few starting with the base spec. In the next one, I plan to go over the RFCs for JWT, Revocation, Inspection, PKCE, the AppAuth pattern, and probably a few others.

Thanks for the note though.


Thanks for the shoutout to AppAuth (https://appauth.io). It’s our 20% project at Google.


Scammy site - see previous discussion:https://news.ycombinator.com/item?id=16576516


I am not sure about you, but as my career as a developer progressed I rely less on Stack Overflow today as I did in the past. To me it seems that this survey may have a strong bias.


Not entirely sure, but is the idea to implement something like https://github.com/emirotin/mongodb-migrations in python? If so, what's the difference to other tools like:

- https://github.com/ClearcodeHQ/migopy

- https://github.com/DoubleCiti/mongodb-migrations


The article doesn't actually talk about preventing injection attacks, but rather identifying potential attack surfaces by doing an AST search for eval/exec in combination with mutable variables. The article does not explain what limitations exist for their runtime check:

> This results in 5 false positives (out of 56 benign inputs), which are caused by limitations of the static analysis (3/5) or node types outside of the safe set (2/5).

Besides that, it's good to see more security tools - especially when the research is open source: https://github.com/sola-da/Synode


Something being apparent (in a certain demographic) does not in any sense reduce the validity of scientific research in this area. There have been great papers on topics like these in the past, some of them even award-winning and read-worthy.


>worth-ready

Read-worthy for anyone who was a bit high like me and did a double take (sorry if this is against etiquette, I don’t have anything substantial to add to what you said)


Oops, not sure what went on in my head there. Corrected!


Were are you reading that? It's a long report but I wasn't able to find what you're referring to. Would be awesome if you could clarify!



Towards the end. Ctrl+f developer story.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: