在React应用中使用Facebook Client访问令牌嵌入Instagram,使用Facebook客户端访问令牌安全吗
我正在使用 react-instagram-embed 在我的react App中嵌入Instagram post 。
为了能够使用Instagram,我需要 nofollow noreferrer“> client
客户端访问令牌
如果您的应用必须访问用户代理的OEMBed端点,例如 移动设备或Web浏览器,您的应用必须使用客户端访问 令牌并将受到客户令牌率限制的约束。
要获取客户端访问令牌,请登录您的应用仪表板,然后 导航到设置>高级安全>客户令牌。
与应用程序访问令牌不同,客户端访问令牌不能在 他们必须独自启用端点请求,它们必须与您的 应用ID。为此,请将您的令牌附加到应用ID的末尾, 用管道符号(|)隔开:
{app-id} | {client-token}
例如:
access_token = 1234 | 5678
当我在浏览器中检查源时Facebook app-id
和<代码>客户端在客户端中公开。
它是安全的,这不会引起安全问题?
I am using react-instagram-embed to embed instagram post in my React app.
To be able to use instagram I need the Client Access Token:
Client Access Tokens
If your app must access the oEmbed endpoint from a user agent such as
a mobile device or web browser, your app must use a Client Access
Token and will be subject to Client Token Rate Limits.To get a Client Access Token, sign into your App Dashboard and
navigate to Settings > Advanced > Security > Client Token.Unlike App Access Tokens, Client Access Tokens cannot be used in
oEmbed endpoint requests on their own, they must be combined with your
App ID. To do this, append your token to the end of your App ID,
separated by a pipe symbol (|):{app-id}|{client-token}
For example:
access_token=1234|5678
When I inspect my source in the browser the Facebook app-id
and client-token
are exposed in the client.
Is it safe and this does not cause security issues?
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
data:image/s3,"s3://crabby-images/d5906/d59060df4059a6cc364216c4d63ceec29ef7fe66" alt="扫码二维码加入Web技术交流群"
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
嵌入分为两种方式。
第一个是从网站上复制并嵌入 blockQuote 标签,
第二个是通过API接收和嵌入 blockQuote 标签。
对于访问令牌,您必须从服务器调用API进行交付。
Embedded is divided into two ways.
The first is to copy and embed the blockquote tag from the website
the second is to receive and embed the blockquote tag as a result through the api.
For access tokens, you must call the api from the server for delivery.