[Michael (top answer)] Is this a valid/practical security concern? For the official Client A, my OAuth2 provider may issue a "super" type/scope token which grants access to both public and private pieces of my API In the general case, you could never rely on an auth token given to a user remaining secret from that user. For example - the user could be running a rooted phone, and read off the token, gaining access to your private API. Ditto if the user's system was compromised (the attacker could read off the token in this case). Put another way, there's no such thing as a "private" API that is at the same time accessible to any authenticated user, so it's reasonable for Android to ignore this security by obscurity goal in its design. a malicious app ...

Context: Stack Overflow #14437096 (top answer, 10 votes, 4 answers): Android's AccountManager appears to fetch the same cached auth token for apps with different UIDs - is this secure? It does not seem compatible with OAuth2, since access tokens are not supposed to be shared between different clients. Background/Context I am building an Android app which uses OAuth2 for authentication/authorization of REST API requests to my server, which is an OAuth2 provider. Since the app is the "official" app (as opposed to a 3rd-party app), it is considered a trusted OAuth2 client, so I am using the resource owner password flow for obtaining an OAuth2 token - the user (th

## Matched source
Source: Published skill
Original query: "Shouldn't Android AccountManager Store OAuth Tokens on a Per-App/UID Basis?"
Key terms: accountmanager, android, basis, oauth, shouldn, store, tokens
