Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Your secrets are out there in public to connect with your Tado. #1

Open
marcofranssen opened this issue Nov 30, 2020 · 1 comment
Open

Comments

@marcofranssen
Copy link

marcofranssen commented Nov 30, 2020

You have committed the client-id and client-secret. Should I turn on the Heat ;-).

FYI: just remove you current secret from Tado so no one can abuse and create a new one, but don't commit it.

@SebastiaanKlippert
Copy link
Owner

Always appreciated for pointing this out, but authentication is done with a username and password which is not committed as far as I can see.

If you are referring to the wZaRN7rpjn3FoNyF5I client secret, that is the client secret for the TADO web app, this is available on the web and can be found in the TADO web app.
I could have added a comment there in my code, but this was just an experiment.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants