*This post is locked for comments
*This post is locked for comments
Thanks for your reply
Hi,
You should implement implicit flow of OAuth2.0 in your app to make the tokens short lived and don't cache them. As your app is an android app implement azure ad application as native client only. Your app would be secure as your token is getting generated on run time and is valid for short period of time.
-Shaminder
Again. It's the problem of key encoding and you're doing it inside your application. Proper forums for your questions - Android/iOS related. Not the problem of Dynamics CRM/365/WebApi.
Thanks for your reply
This is regarding the dynamics crm Web API. We have exposed it via azure app as describe in SDK. And using it in the Android app.
Our main concern is we have encoded the app token in http request to generate the access key.
Everything is working fine but developer is saying that anybody can access to our dynamics crm once they have access key and token and that can be easily accessible by decoding th app. How to tell them that this secure as this is provided by Microsoft
Thanks & regards
Subhash Mahato
Hello,
This forum is dedicated to Dynamics CRM/365 and not to Android/iOS development. Ask your question using proper forum please.
Stay up to date on forum activity by subscribing. You can also customize your in-app and email Notification settings across all subscriptions.
André Arnaud de Cal... 291,253 Super User 2024 Season 2
Martin Dráb 230,188 Most Valuable Professional
nmaenpaa 101,156