Hi,
Someone uses Fiddler to get my access token which is normally hidden from our apps users. Don't they now have access to my Dropbox through the API?
I read some of the other posts about this subject and it appears to not be a major concern.
Is that really the case?
It's not like someone stealing your intellectual property (unless you keep that in DB!) but it seems if someone wanted to - they could do some damage - upload rouge files, download/alter files.
Just a couple thoughts - nothing original:
* Could we have short lived access tokens (or other kind)?
* How about something like permissions on AT - say something like upload-only, etc?
Am I missing something? I want to present a Dropbox based solution to my team for a project and I don't know if this is going to fly. My company is pretty tight about security.
Thanks
Ted