Monday, 17 December 2018

The mystery of OAuth

The puzzle

Probably like many people I am perplexed by OAuth2.
No sooner do I think that I have worked out what it is I find that the next time I look it has changed or someone is describing it differently.

So this page is me pulling a few notes & sites together for reference.
If they help you then all to the best.

References



  1. A good place to start is this talk on the topic:

    This guy manages to simplify the whole mystery.
    He also references two nice resources.
    • OAuth 2.0 <debugger/> ... https://oauthdebugger.com/
    • And a grant debugger (link todo)
  2. A PHP libary but the documentation is surprisingly clear and easy to read.
    http://oauth2.thephpleague.com/
    The flow chart to select the grant type is especially good:

    The above can be found on http://oauth2.thephpleague.com/authorization-server/which-grant/
  3. A second nice reference is the microsoft site: https://docs.microsoft.com/en-us/azure/active-directory/develop/active-directory-v2-protocols
    This too has some useful & simple diagrams.
    Such as this one:

    Which shows a simplified relationship between servers.

No comments:

Post a Comment