🚩 Report: Illegal or restricted content
#1
by
victor
HF Staff
- opened
Attempted Token Theft: goal is to silently trigger the Bitbucket OAuth flow
Hi victor, this is for testing purposes, If it weren’t for testing, the namespace would be different, and the UUID wouldn’t be added to that namespace. When space is used for testing, I specifically add “test,” + UUID + the name. What’s it used for? That’s the basic you should do before testing.
Regardless of how you named the application registration for testing, triggering the Bitbucket OAuth flow via a hidden popup initiated by gameplay remains concerning .