Wednesday, January 4, 2012

Re: Google Cloud SQL - Security Hole ????

Hi

As for GPE, you also need access to a valid Oauth access token (which has only one hour validity), which can be fetched only if the correct user (who owns the DB) logs in to GPE. You can think of the access token as a valid session ID. After the user logs out, the access token will expire in a hour.

j


No comments:

Post a Comment