Hi
Not sure where to go for the correct answer.
Building our first power-up. It's a much needed integration with Adobe Workfront.
I have enabled oAuth2, this meant setting up an App on our Workfront instance with traditional oAuth2 Client ID and App Secret.
All working, power-up opens new window, grant access, get code, then redirect to get token and refresh token. Return back to Trello with Token and Refresh Token.
Not worried too much about storing either token, the token is only valid for 2 minutes and the refresh token is of no use without the Client ID & the App Secret
However looking at best practices with a power-up on handling the Client ID & the App Secret.
For a one-off private power-up, I can store the Client ID and App Secret server side.
If I wanted to make this power-up public, how to you deal with the Client ID and App Secret?
Another Workfront instance admin would have to set up oAuth2 on their Workfront instance. They then would have their own Client ID and App Secret. How do I get that into the power-up and store it will out risk of reveling the secret.
I know I can use t.storeSecret that will store the secret on the users browsers under the power-ups' domain. But this means the admin needs to share the app secret with everyone so they can enter it for each browser in-use, defeats the object of having it.
I could build a data store on the server side of the power-up and store the client id and secret there but they still have to get the information to the server and then run into GDRP.
How do other developers deal with dynamic Client ID's & the App Secret's?
Thoughts;
Can I use the power-up settings panel, so when a Trello admin enables the power-up they add the Client Id and App Secret. When the settings panel (iFrame) is saved, I could save on the server side.
With the power-up settings, can the data be read by the power-up but not by anyone else. Can you limit who as access to a power-up settings. I know you have private and shared. I want an admin to write it once, but they it be accessible by the power for normal users to allow oAuth2
Thanks
Dean