动态

讨论OAuth泄漏责任归属及工程实践问题

Gergely Orosz
Fair point from Zach that in the case of OAuth, if these leak, the impact can be hard to tell as the vendor.

Other points still stand: no single individual taking responsiblity; removing certifications; no postmortem shared are all red flags
Zack Korman
@GergelyOrosz 稍微辩护一下:我不太了解 Google 生态系统,但对于 Microsoft 应用程序,应用所有者无法获取审计日志,只有客户能(有一些很好的理由说明为什么这样,但也有很好的理由说明应该反过来)。
动态Gergely Orosz2026-04-20原文

相关内容