Home | Notifications | New Note | Local | Federated | Search | Logout
Note Detail
Reply to @sun@shitposter.world
ロミンありん@romin@shitposter.world (2026-08-15 21:46:45)
@sun the scenario is more like rogue miniapp operator has access to all other miniapps out there for a particular user he got a token from
---Reply---
Blurry Moon@sun@shitposter.world (2026-08-15 21:50:07)
@romin let me go over the flow again to make sure that the handoff can’t be faked by a miniapp with an existing token. That is the only mechanism where that could happen.
Reply
---Replies---
Blurry Moon@sun@shitposter.world (2026-08-15 21:52:10)
@romin this is just normal oauth flow so if this was vulnerable everything would be