02-01-2016 05:46
- Mark as New
- Bookmark
- Subscribe
- Permalink
- Report this post

02-01-2016 05:46
- Mark as New
- Bookmark
- Subscribe
- Permalink
- Report this post
How i should configure Callback URL for use app in many subdomains (near 1000) (sub1.example.com, sub2.example.com and etc)

02-01-2016 10:44
- Mark as New
- Bookmark
- Subscribe
- Permalink
- Report this post



02-01-2016 10:44
- Mark as New
- Bookmark
- Subscribe
- Permalink
- Report this post
This is an unusual use case. Can you please explain what you're doing?
You'll likely hit the character limit (3000) before you can add that many redirect URIs.

02-01-2016 10:57
- Mark as New
- Bookmark
- Subscribe
- Permalink
- Report this post

02-01-2016 10:57
- Mark as New
- Bookmark
- Subscribe
- Permalink
- Report this post
Our solution automatically assigns a subdomain based on the health club chains name.
We are keen to have a solution whereby we can allow each of the club chains to leverage our existing cuttingedge.fisikal.com.
Is this something you can accommodate?
Best wishes,
Rob Lander
CEO
www.fisikal.com

02-01-2016 11:14
- Mark as New
- Bookmark
- Subscribe
- Permalink
- Report this post



02-01-2016 11:14
- Mark as New
- Bookmark
- Subscribe
- Permalink
- Report this post
It's not something that we plan on supporting, at least in the near term.
We strongly recommend that apps that act on behalf of another company register an app on dev.fitbit.com for each of their customers. Otherwise, you'll need to use a more generic redirect URI for all of your customers' customers.

02-01-2016 11:24
- Mark as New
- Bookmark
- Subscribe
- Permalink
- Report this post

02-01-2016 11:24
- Mark as New
- Bookmark
- Subscribe
- Permalink
- Report this post
Are you able to white label *cuttingedge.fisikal.com at all?
Best wishes,
Rob Lander
CEO
www.fisikal.com

02-01-2016 11:51
- Mark as New
- Bookmark
- Subscribe
- Permalink
- Report this post



02-01-2016 11:51
- Mark as New
- Bookmark
- Subscribe
- Permalink
- Report this post
No, we don't have that ability. The OAuth 2.0 specification requires an exact match for good security reasons. (Other OAuth 2.0 providers only match on hostname, not full URI, but even in that situation, it's unreasonable to expect to match more than a couple hostnames.)

02-16-2016 13:51
- Mark as New
- Bookmark
- Subscribe
- Permalink
- Report this post

02-16-2016 13:51
- Mark as New
- Bookmark
- Subscribe
- Permalink
- Report this post
We have the exact same issue. Is there a way to expand the 3,000 character limit? This only allows us access to roughly 42 different hostnames.

02-19-2016 11:13
- Mark as New
- Bookmark
- Subscribe
- Permalink
- Report this post



02-19-2016 11:13
- Mark as New
- Bookmark
- Subscribe
- Permalink
- Report this post
How much bigger would you need it to be? This is really going against our intent—we don't want to match a bunch of different hostnames for a single app. It's more of a convenience for apps that have multiple environments (QA, staging, production, etc).

02-23-2016 07:52
- Mark as New
- Bookmark
- Subscribe
- Permalink
- Report this post

02-23-2016 07:52
- Mark as New
- Bookmark
- Subscribe
- Permalink
- Report this post
We have over 130 different subdomains (and growing) but we found a different solution with logging in the user that is sent back through the state addition, then forwards them back to their original subdomain after completing the fitbit process. But we're not keen on sending information that could log someone in via the state method if at all possible.

02-23-2016 10:48
- Mark as New
- Bookmark
- Subscribe
- Permalink
- Report this post

02-23-2016 10:48
- Mark as New
- Bookmark
- Subscribe
- Permalink
- Report this post
@thidev wrote:But we're not keen on sending information that could log someone in via the state method if at all possible.
Then don't pass that information. You can put whatever value in there you'd like. It doesn't have to be the same value of your cookie session or something. You could just use the subdomain of origin and no user-specific information.

