Explain it to Me Like I’m 5: Oauth2 and OpenID

  Рет қаралды 69,500

SpringDeveloper

SpringDeveloper

Күн бұрын

OAuth2 and OpenID Connect are quickly becoming mainstays for application developers. Companies want integrated authentication to reduce security footprints and users expect the convenience of single sign-on. As an application developer, it’s up to you to facilitate this in your applications.
In this talk, you’ll learn about OAuth2 and OpenID Connect. The focus will be on concepts and terminology, which is standard across OAuth2 providers and implementations, with the specific goal of presenting them in the simplest way possible. The session will also demonstrate how the concepts covered are used as you interact with OAuth2 providers and develop your Spring Boot and Spring Security applications.
The goal of this session is that you walk out with practical knowledge about OAuth2 and OpenID connect and the confidence to implement these technologies in applications you develop at your company.
Daniel Mikusa: Senior Staff Technical Support Engineer at VMware
Slides: www.slideshare.net/Pivotal/ex...

Пікірлер: 32
@sara-subramanian
@sara-subramanian 2 жыл бұрын
Succinct and yet so illustrative! Learnt a thing or two about technical presentations too! Great presentation and presenter!
@igorilievski6634
@igorilievski6634 2 жыл бұрын
Insanely good. I was already familiar with this concepts, but now I actually can communicate them to nontechnical personal. Great presentation!
@MrMeMyselfMe
@MrMeMyselfMe 3 жыл бұрын
Awesome presentation!
@KeyserTheRedBeard
@KeyserTheRedBeard 3 жыл бұрын
neat upload SpringDeveloper. I crushed that thumbs up on your video. Keep on up the really good work.
@janigerud
@janigerud 2 жыл бұрын
Really great explanation!!! Big thanks for making it
@richardlanglois5183
@richardlanglois5183 3 жыл бұрын
Great presentation!
@abayansal
@abayansal Жыл бұрын
fantastic explanation of oauth and openid!!!
@RaviYasas
@RaviYasas 3 жыл бұрын
Nice explanation !!!
2 жыл бұрын
Great talk!
@alexauto4578
@alexauto4578 2 жыл бұрын
This is very useful even if I am a little bit above 5 :)
@zoladkow
@zoladkow 3 жыл бұрын
@33:20 i'd say that a wrist band is the analog of an access token (you can go out and back in to the party) while for an id token that would be a badge (name & photo, etc)... 🙃
@idealdev7945
@idealdev7945 3 жыл бұрын
Awesome!
@numankaraaslan
@numankaraaslan 3 жыл бұрын
Yep, i am a 5 year old because this worked for me :) Thanks.
@sergiogomez189
@sergiogomez189 2 жыл бұрын
do you have any example using : (Client Initiated Backchannel Authentication, keycloak and spring boot) please
@ec9386
@ec9386 Жыл бұрын
33:15 Why is the ticket booth is called authorization server? It checks your identity, so it should be authentication, right? Please correct me if my understanding is wrong, thanks!
@evgeniyrymko8520
@evgeniyrymko8520 11 ай бұрын
It's top!👍
@AjayKumar-fd9mv
@AjayKumar-fd9mv Жыл бұрын
Thanks
@alive-awake
@alive-awake Жыл бұрын
I guess i need it explained to me as if I was a 2 yr old.
@TimBee100
@TimBee100 3 жыл бұрын
Can't the bearer token be of JWT format?
@IvanRandomDude
@IvanRandomDude 3 жыл бұрын
It can be of any format. OAuth specification doesn't define format of the tokens. You can generate your own tokens if you want.
@veroniquenollet7718
@veroniquenollet7718 2 жыл бұрын
Where can I get the presentation so I can click the links? thanks!
@veroniquenollet7718
@veroniquenollet7718 2 жыл бұрын
I found it. SOLVED!
@tuacademiadeinformatica2542
@tuacademiadeinformatica2542 2 жыл бұрын
@@veroniquenollet7718 ¿where is it??
@peternagy3654
@peternagy3654 4 ай бұрын
The speaker explains: OAuth2 focusing on what a person can do, not who that person is. Later he tells, OIDC is extension of OAuth2 which implements the authentication, or identity. OIDC focus is to prove who someone, not what they can do. Am I the only one feel confused? Please correct me if I'm wrong, but in the original OAuth2 (without the OIDC extension) authenticating the user was the authorization-server responsibility. Based on the successful authentication, it could determine the authorities of the user. These authorities (stored in the issued token) provided information to the underlying services to make authorization related decisions. So what the OIDC add to this flow? What is the purpose of the separated access and id token. What problem this separation solves? What should we store on each and when should we use them? Can you please explain that like I'm 40+ year old, no need to lower down that much.
@alive-awake
@alive-awake Жыл бұрын
Why is AOL making me agree to these terms for my e-mail account?
@poloolo69
@poloolo69 Ай бұрын
goat
@ykli1399
@ykli1399 2 жыл бұрын
is slideshare broken? i can't open the slides :(
@dongshengzhang4105
@dongshengzhang4105 Жыл бұрын
Which 5-year-old kid can stand for almost 50 minutes of lecture???
@randomlyswatching9481
@randomlyswatching9481 Жыл бұрын
😂
@coolkoala282
@coolkoala282 Жыл бұрын
🤣
@vidsjust8349
@vidsjust8349 Жыл бұрын
boaring
Spring Security Patterns
54:26
SpringDeveloper
Рет қаралды 28 М.
Do’s and Don’ts: Avoiding First-Time Reactive Programmer Mines
58:38
DO YOU HAVE FRIENDS LIKE THIS?
00:17
dednahype
Рет қаралды 36 МЛН
ОДИН ДЕНЬ ИЗ ДЕТСТВА❤️ #shorts
00:59
BATEK_OFFICIAL
Рет қаралды 8 МЛН
Неприятная Встреча На Мосту - Полярная звезда #shorts
00:59
Полярная звезда - Kuzey Yıldızı
Рет қаралды 7 МЛН
1 or 2?🐄
00:12
Kan Andrey
Рет қаралды 27 МЛН
Getting Started with Spring Authorization Server
54:21
SpringDeveloper
Рет қаралды 40 М.
Security Patterns for Microservice Architectures
40:30
SpringDeveloper
Рет қаралды 24 М.
Securing Microservices with Spring Cloud Security
1:29:52
SpringDeveloper
Рет қаралды 100 М.
Configuring and Extending Spring Authorization Server
38:40
SpringDeveloper
Рет қаралды 13 М.
Spring for Architects
59:46
SpringDeveloper
Рет қаралды 27 М.
Multi-tenancy OAuth with Spring Security 5.2
1:11:23
SpringDeveloper
Рет қаралды 30 М.
Spring Tips: The Spring Authorization Server
22:21
SpringDeveloper
Рет қаралды 15 М.
Securing OAuth 2.0 Resources in Spring Security 5.0
1:11:14
SpringDeveloper
Рет қаралды 50 М.
Spring Cloud Gateway for Stateless Microservice Authorization
36:32
SpringDeveloper
Рет қаралды 42 М.
Main filter..
0:15
CikoYt
Рет қаралды 13 МЛН