chris

关于我

开发者信息
名称 chris
注册时间 March 15, 2026
开发的附加组件数量 0 个附加组件
开发的附加组件平均得分 尚无评分

我所发表的评价

oneClipper - send mail to one Note

评分3星,满分5星

I appreciate the work behind oneClipper and wanted to share a constructive security observation from reviewing the source code.

The add-on appears to rely on an external token server for Microsoft OAuth token handling, so users may need to place significant trust in that service. If that server were ever compromised or mismanaged, connected OneNote access could potentially be exposed.

It may be helpful to clarify this external dependency on the add-on page so users can better understand the trust model. I’m sharing this as a constructive suggestion for transparency, not as an accusation.

oneClipper - send mail to one Note

评分3星,满分5星

I appreciate the work behind oneClipper and wanted to share a constructive security observation from reviewing the source code.

The add-on appears to rely on an external token server for Microsoft OAuth token handling, so users may need to place significant trust in that service. If that server were ever compromised or mismanaged, connected OneNote access could potentially be exposed.

It may be helpful to clarify this external dependency on the add-on page so users can better understand the trust model. I’m sharing this as a constructive suggestion for transparency, not as an accusation.

对这个附加组件,此用户曾发表过1个评价