Skip to content

Feature Request: Use Refresh Token #248

Discussion options

You must be logged in to vote

I've tried using a standardized OAuth library before, but unfortunately didn't succeed.
BMW has implemented some additional obscurity layers to its API, so it is not as easy as compared to e.g. the Github OAuth flow.

I do get your point in regard to storing you username/password credentials. However from what I understand of refresh tokens (not a security engineer here) it would only add security by obscurity.
Refresh tokens are long lived and might not even expire when you change your accounts password (depends what BMW has implemented). They need to be stored at the same security levels than username and password.

We quickly got some other implications coming up such as what are we goin…

Replies: 3 comments

Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Answer selected by gerard33
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
3 participants