Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6609469
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 25, 20262026-05-25T19:43:18+00:00 2026-05-25T19:43:18+00:00

According to facebook oauth2 docs, client side flow doesn’t require client secret param. Client

  • 0

According to facebook oauth2 docs, client side flow doesn’t require client secret param. Client side flow can be used on both native and mobile web apps.

However google’s native oauth2 flow require client secret http://code.google.com/apis/accounts/docs/OAuth2.html#IA.

In this case client secret can be stolen by hacker using reverse engineering tools.

Can somebody clarify why it was done this way?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-25T19:43:19+00:00Added an answer on May 25, 2026 at 7:43 pm

    According to a post from a Googler, the main reason is that they use the same libraries for server-side apps and native apps. It sounds like they don’t consider client_secret to be sensitive in the context a native app, but they plan to phase it out for the installed app flow eventually.

    From https://groups.google.com/group/oauth2-dev/browse_thread/thread/1e714924ebcc7e60/edfaaad5830ff2e8 :

    We don’t expect those secrets to stay secret—so far we’re including them mostly so it’s convenient to use with libraries today, and expect to stop requiring them at some point in the future.

    While that might sound bad, keep in mind that OAuth was never intended to prevent malicious users from forging requests in the context of your mobile/desktop app.

    If you’re concerned about exposing client_secret, there is also the client-side flow described here: http://code.google.com/apis/accounts/docs/OAuth2.html#CS As far as I can tell, the client-side flow doesn’t require client_secret and would work fine from a desktop or mobile app.

    -Chris

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

According to Facebook graph API we can request a user profile picture with this
According to the Facebook Graph API documentation , the fields param acts as a
According to this discussion , the iphone agreement says that it doesn't allow loading
According to what I have found so far, I can use the following code:
According to the feedparser documentation , I can turn an RSS feed into a
According to this Wikipedia entry: Protocol Buffers is very similar to Facebook’s Thrift protocol,
According to the Facebook API documentation, most of the work is handled through javascript.
Possible Duplicate: Html validation error for property attribute According to facebook to use their
According to the Facebook developer roadmap , it will soon be possible to put
According to this video http://www.facebook.com/video/video.php?v=562087699610 modern browsers break same origin policy so javascript can

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.