apigee / api-platform-samples

Working samples for the Apigee API Platform
Apache License 2.0
498 stars 713 forks source link

Important *not* to include client credentials but then we do #86

Open bertramn opened 7 years ago

bertramn commented 7 years ago

Could you please clarify what below comment means? It states "its important not to include it" but then it is included. Also can you please expand on how exactly a caller might gain access tokens from that endpoint without supplying consumer key and secret? I am a bit scared to install this after reading the comments! Many thanks.

https://github.com/apigee/api-platform-samples/blob/a0ececb6ef80de0d66f8b708294abf6ff42949ae/default-proxies/oauth/apiproxy/policies/GenerateAccessTokenClient.xml#L7-L10