When Basic OAuth Is Not Enough
5 Views
admin
03 Dec 2019
A talk given by Michał Trojanowski from Allegro.pl at the 2019 Platform Summit in Stockholm.
OAuth 2.0. gives you some great tools in terms of authorising access to resources. It works very well in web environments but falls short when working with APIs, e.g. when you want to run the API in a GUI-less environment or use the API from a client machine (think of a desktop or mobile app). Thankfully there are some extensions to the RFC that help alleviate those problems. In the talk I would like to present the concepts of Device Grant, proof key of code exchange and the token exchange flow – different OAuth extensions which can be really helpful when working with APIs.
-
Category
Show more
Facebook Comments
No comments found