🚩 Report: Illegal or restricted content

#1
by victor HF Staff - opened
HF Staff

Attempted Token Theft: goal is to silently trigger the Bitbucket OAuth flow

HF Staff

That's quite bad @psych012 :/

Hi victor, this is for testing purposes, If it weren’t for testing, the namespace would be different, and the UUID wouldn’t be added to that namespace. When space is used for testing, I specifically add “test,” + UUID + the name. What’s it used for? That’s the basic you should do before testing.

HF Staff

Regardless of how you named the application registration for testing, triggering the Bitbucket OAuth flow via a hidden popup initiated by gameplay remains concerning .

Now i add "for testing purpose" in the game before starting , i hope it solve the issue.

image.png

Your need to confirm your account before you can post a new comment.

Sign up or log in to comment