yadayada / acd_cli

An unmaintained command line interface and FUSE filesystem for Amazon (Cloud) Drive
Other
1.35k stars 165 forks source link

access_token and refresh_token forwarded through developer website... #526

Open Grimeton opened 7 years ago

Grimeton commented 7 years ago

Hello,

it should be CLEARLY MENTIONED IN THE README AND THE OTHER DOCS THAT USING THE OAUTH METHOD WITHOUT YOUR OWN SECURITY PROFILE FORWARDS THE auth_token AND THE refresh_token VIA THE DEVELOPERS WEBSITE EACH HOUR. THIS OPENS A DOOR FOR PEOPLE HAVING ACCESS TO THE SERVER TO ACCESS YOUR CLOUD DRIVE AND ALL YOUR DATA.

https://github.com/yadayada/acd_cli/blob/master/acdcli/api/oauth.py line 192 and following.

I personally don't like it but If people want to go with that option they should be CLEARLY WARNED that this is the case. Independent of what source code is shown to be running on the website.

Cu