Announcements

Help Wizard

Step 1

NEXT STEP

Topics with Label: Security

Labels

Forum Posts

February 2026 Spotify for Developers update: thread

Hey everyone, I’ve created this thread to provide an open space for discussion, feedback, concerns or ideas on an upcoming update to Spotify for Developers access. We’ve shared a blog post that explains what’s changing and why. Please use this thread...

Spotify

CoolAssPuppy

Visitor

85194 Views

339 replies

28 likes

S4D
  • 85194 Views
  • 339 replies
  • 28 likes

Cross-Site Request Forgery (CSRF) Vulnerability in Spotify Logout Feature

Hello Spotify Team,I am writing to report a potential Cross-Site Request Forgery (CSRF) vulnerability within the Spotify platform, specifically related to the logout feature.For confidentiality reasons, I’m not providing further details in this messa...

Casual Listener

Hello Spotify Team, I am writing to report a potential Cross-Site Request Forgery (CSRF) vulnerability within the Spotify platform, specifically related to the logout feature. For confidentiality r...

medjahdi31

Casual Listener

434 Views

2 replies

0 likes

Account Issues
bug
Security
  • 434 Views
  • 2 replies
  • 0 likes

Solved!! Dynamic CDN domains for images?

Gooday, I would like to ask if the CDN's where the images are hosted are always the same or change overtime? I'm using NextJS and need to whitelist these domains for my images.This is what I'm trying to do: https://nextjs.org/docs/api-reference/next/...

Newbie

...ou provide me with a list all used domains for the images? Or put it in the documentation?   This would help with image optimization and security in apps.   Thanks.      

yashasewi

Casual Listener

5280 Views

2 replies

2 likes

api
cdn
Images
Security
  • 5280 Views
  • 2 replies
  • 2 likes

Possible security bug in the web api auth example from gitbub

I've cloned the code from: https://github.com/spotify/web-api-auth-examples and possibly found some security bug - but please correct me and explain why I'm wrong if that is the case. State is set in /login route to var state = generateRandomString(1...

Music Fan

I've cloned the code from: https://github.com/spotify/web-api-auth-examples and possibly found some security bug - but please correct me and explain why I'm wrong if that is the case.   S...

753 Views

0 replies

0 likes

Security
  • 753 Views
  • 0 replies
  • 0 likes