Client Credentials Grant Flow is REALLY BAD

  Рет қаралды 4,173

Michael Bissell

Michael Bissell

Күн бұрын

Пікірлер: 9
@ygorcosta6893
@ygorcosta6893 11 ай бұрын
It depends a lot on the system's requirements. For instance, if you need to make this query on the front end, you leave the client ID and secret on the backend. After receiving the token, you can then use it securely on the front end. However, it's essential to restrict the token's lifespan; otherwise, it won't be effective.
@MortenHolje
@MortenHolje Жыл бұрын
Hi Michael, thanks for great videos about grant flows. I think you should have specified that the auth service grants tokens which you use to consume resources from an API. It's alot better than using API keys. Still learning, so please correct me if im wrong here (anyone, not just Michael).
@benpracht2655
@benpracht2655 Жыл бұрын
What should be done instead? How would you handle an automated request from another backend service?
@Renanfg
@Renanfg 10 ай бұрын
so this flow is good for backend to backend since there's no exposure
@kaustubh1871
@kaustubh1871 Жыл бұрын
Hi, Great Explanation. I was really clear and was on point! It would be great if you could make a similar one for implicit grant and resource owner credentials grant. Thank you.
@ScrotoTBaggins
@ScrotoTBaggins Жыл бұрын
I little simplistic to just say client credentials bad
@bissellator
@bissellator Жыл бұрын
They're simply unsecure.
@longb1913
@longb1913 Жыл бұрын
what to use instead then@@bissellator
@rhysevancampbell
@rhysevancampbell 3 ай бұрын
@@bissellator I kind of agree with the comment. Bad for what? What is the better approach? And in what situation?
A Very Simple API Call
2:17
Michael Bissell
Рет қаралды 3,1 М.
Swagger Azure AD Client Credentials Flow with  net core web api
27:17
AzureTeach•Net
Рет қаралды 3,3 М.
It works #beatbox #tiktok
00:34
BeatboxJCOP
Рет қаралды 41 МЛН
Try this prank with your friends 😂 @karina-kola
00:18
Andrey Grechka
Рет қаралды 9 МЛН
Каха и дочка
00:28
К-Media
Рет қаралды 3,4 МЛН
Основы OAuth 2.0 и OpenID Connect #oauth #oidc #openidconnect
1:10:17
Уголок сельского джависта
Рет қаралды 12 М.
Session Vs JWT: The Differences You May Not Know!
7:00
ByteByteGo
Рет қаралды 312 М.
Oauth 2.0 Client Credential Flow | Microsoft Graph
10:37
Concepts Work
Рет қаралды 35 М.
OAuth Grant Types simplified for decision makers
13:16
Software Architecture and Design
Рет қаралды 12 М.
ID Tokens VS Access Tokens: What's the Difference?
8:38
OktaDev
Рет қаралды 188 М.
OAuth 2.0 - a dead simple explanation
9:16
Jan Goebel
Рет қаралды 27 М.
OAuth Authorization code flow
11:49
Jan Goebel
Рет қаралды 55 М.
Get started with OAuth 2.0 On-Behalf-Of flow | Microsoft Entra ID
15:55
Microsoft Security
Рет қаралды 9 М.
It works #beatbox #tiktok
00:34
BeatboxJCOP
Рет қаралды 41 МЛН