What is the difference between using steemlogin and the Dapp storing the keys into Firestore themselves?
The success/failure URL is exposed to the public, what is the process for the dApp success/failure script to validate the code being received is really coming from steemlogin and not some spoofed data?