Set this up a while ago using the old railscasts tutorial. BUT how on earth do you secure the route to /oauth/applications.... On my production site I don't want people to be able set up new appplications to connect to, as this is part of my saas service

Images are stored from one rails app, but records are syncronised to another app via graphql. What is the option for the second app to delete the record from itself without destroying the original asset uploaded from the first app?