Skip to content

Conversation

tuthanika
Copy link

No description provided.

@willnode
Copy link
Member

That's not logto API at all

@willnode willnode closed this Aug 26, 2025
@tuthanika
Copy link
Author

this is api to get oauth2 token by Client id and Client secret

@willnode
Copy link
Member

Please share documentation proofing these domain is listed

@tuthanika
Copy link
Author

tuthanika commented Aug 26, 2025

I use alist / openlist
https://doc.oplist.org/guide/drivers/onedrive_app
https://doc.oplist.org/guide/drivers/febbox

Post "https://api.febbox.com/oauth/token": dial tcp 43.154.95.27:443: connect: connection refused

Post "https://login.microsoftonline.com/cb29385f-3abb-4c02-b2c0-5df2693d7e7e/oauth2/token": dial tcp [2603:1046:2000:190::1]:443: connect: connection refused

@willnode willnode reopened this Aug 26, 2025
@willnode
Copy link
Member

willnode commented Sep 3, 2025

I feel uneasy to allow login.microsoftonline.com, it make someone could attempt to brute force login. Can you find a way such that the server won't talk to it?

@tuthanika
Copy link
Author

If you feel uneasy about it, you can skip it, because security should always come first. I think for now, there's no other solution since it's the officially recommended method by Microsoft

@tuthanika
Copy link
Author

"Openlist/alist supports the 'Use online API' feature with the API URL address: https://api.oplist.org/onedrive/renewapi. It might serve as a replacement for "login.microsoftonline.com".
EX: GET https://api.oplist.org/onedrive/renewapi?driver_txt=onedrive_pr&refresh_ui=xxxx."

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants