Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Implications of using api secrets in a public environment? #342

Open
Haarolean opened this issue Jan 22, 2024 · 0 comments
Open

Implications of using api secrets in a public environment? #342

Haarolean opened this issue Jan 22, 2024 · 0 comments

Comments

@Haarolean
Copy link

Hi,

more of a question actually, rather than an issue. Couldn't find the answer to my question anywhere else so decided to raise one here.

As stated in README, running the app requires an app id and secret token from my.telegram.org, where, in turn, it's stated for both id and hash, that "it's forbidden to pass this value to third parties". As far as the client is frontend-only, running it with secrets will get the tokens expose to the end user, and obfuscation here can't be called quite a secure way to prevent one from reading it.

This raises further questions, is that possible to run the app in a publicly accessible environment, or should I run it exclusively for my personal use? If the latter, how is the app being run on web.telegram.org itself?

Really hope to get the answers, thanks!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant