Open valpackett opened 12 years ago
This text could be clearer. But the bottom line is, the secret is not used in the client-side flow. I've used this flow in my own 100% browser app (App Passant) and it works fine.
That's the issue… This line of documentation is confusing
auth.md:
How can I keep my client_secret confidential if I want to build a 100%-browser JavaScript app? How is the secret used? I don't see it in the URL examples of the client-side flow.