FlareStart
HomeNewsHow ToSources
FlareStart

Where developers start their day. All the tech news & tutorials that matter, in one place.

Quick Links

  • Home
  • News
  • Tutorials
  • Sources
  • Privacy Policy

Connect

© 2026 FlareStart. All rights reserved.

Back to articles
It's super safe putting an access token as URL paramater ... right?
NewsWeb Development

It's super safe putting an access token as URL paramater ... right?

via Dev.to WebdevGuy Domino1mo ago

My mom uses this certain website to send out birthday cards to her grandkids. She writes a silly poem, puts in a bunch of pictures, the site prints it up and mails it. Nice card. Cheaper than Hallmark. All that to say that this is a sophisticated and pretty well designed web site; they have developers who know their stuff. Today, she wanted to show someone a card she was working on. So she clicks the share button on her iPad. She doesn't know this is a Safari thing and not a website thing. Safari texts her friend a url. Basically this: https://app.---redacted---.com/not-a-real-url?access_token=blahblahblah-youknowwhatitlookslike They get her text message, click it and, bam 🤯, complete and total access to her entire account. Want to send a card? Sure! Send a thousand cards? Why not. Change her email and password? Go right ahead. We won't even email you to tell you we did any of that stuff! She finally asks me for help and I have her her log out, change her password. Nothing expires the

Continue reading on Dev.to Webdev

Opens in a new tab

Read Full Article
20 views

Related Articles

Aston Martin Valhalla (2026) Review: A $1 Million Plug-In Hybrid
News

Aston Martin Valhalla (2026) Review: A $1 Million Plug-In Hybrid

Wired • 16h ago

The Architect’s Secret: The Patterns That Solve 90% of Real-World Problems
News

The Architect’s Secret: The Patterns That Solve 90% of Real-World Problems

Medium Programming • 16h ago

Deep Dive into Functions: dir(), pip, Default Args, *args, **kwargs, Type Hints, Positional/Keyword…
News

Deep Dive into Functions: dir(), pip, Default Args, *args, **kwargs, Type Hints, Positional/Keyword…

Medium Programming • 16h ago

Stop Writing Clever Code
News

Stop Writing Clever Code

Medium Programming • 16h ago

Anthropic’s Claude Code Source Code Leaked: The npm .map Blunder That Exposed Everything
News

Anthropic’s Claude Code Source Code Leaked: The npm .map Blunder That Exposed Everything

Medium Programming • 16h ago

Discover More Articles