logoalt Hacker News

Mic92today at 3:55 AM1 replyview on HN

I skipped over the first few ones and haven't seen critical ones. The hardcoded oauth client secrets is basically present in any open-source or commercial app that is distributed to end users. It doesn't break the security of end users. It mainly allows other apps to impersonate this app, i.e. present itself as clawdbot, which is a moot point given anyone can just change /inject code into it.


Replies

xtagontoday at 5:03 AM

Yeah, I see what you're saying.