Self-service flows: Understanding security warning on documentation #140
-
Hi on the Kratos Self-service documentation site there is written the following
I don't get this warning on this page, because on the same page there are explanations for browser apps like
What is now correct? a) Never use API Self Service flows within browsers (I think that a react spa, next or PHP is a browser application) |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment
-
The docs distinguish between API-based flows and Browser-based flows. The Guides are specifically for browser flows, and actually consistent with the warning: Don't use the flows where API interaction is required (mobile app, Smart TV, ...) in a web browser. "All Self-Service Flows (User Login, User Registration, Profile Management, Account Recovery, Email or Phone verification) support these two flow types and use the same data models but do use different API endpoints." |
Beta Was this translation helpful? Give feedback.
The docs distinguish between API-based flows and Browser-based flows. The Guides are specifically for browser flows, and actually consistent with the warning: Don't use the flows where API interaction is required (mobile app, Smart TV, ...) in a web browser.
"All Self-Service Flows (User Login, User Registration, Profile Management, Account Recovery, Email or Phone verification) support these two flow types and use the same data models but do use different API endpoints."