Implementing OpenID Connect and OAuth 2.0 - Tips from the Trenches - Dominick Baier

  Рет қаралды 3,410

NDC Conferences

NDC Conferences

Күн бұрын

Don't forget to check out our links below!
ndcporto.com/
ndcconferences.com/
There are typical architectural patterns around identity & access control for modern applications (micro services or cloud-native apps - or whatever you like to call them). OpenID Connect and OAuth 2.0 are the enabler for these architectures. When building such an application system, you will inevitably run into some challenges and questions like which protocol flow to choose, how to design your resources and tokens, how to connect your various (new and old) clients to the token-based system, how to design session and token lifetime management, how to deal with revocation, authentication vs authorization etc.
In this session we will have a look at some common patterns (and maybe anti-patterns) on designing token-based systems and get some answer for the above questions.

Пікірлер: 3
@santiagocavanna
@santiagocavanna 2 жыл бұрын
Thanks for sharing this information. I found it very clear and useful. I am doing some work as IAM Arch and not always it is clear the path.
@volkerdr.milbrandt7692
@volkerdr.milbrandt7692 4 жыл бұрын
- The less claims you need the better. - Only introduce scopes when you need them. - Resource Indicators spec to define relation between resources and scopes can now used to separate tokens between APIs
@volkerdr.milbrandt7692
@volkerdr.milbrandt7692 4 жыл бұрын
OAuth 2.1 protocol flows start 27:38 - changed and simpified: only remaining authorization code flow and client credential work flow
لااا! هذه البرتقالة مزعجة جدًا #قصير
00:15
One More Arabic
Рет қаралды 24 МЛН
Получилось у Миланы?😂
00:13
ХАБИБ
Рет қаралды 6 МЛН
Clean Architecture with NET 8
54:38
NimblePros
Рет қаралды 2,7 М.
Stop, Intel’s Already Dead!
13:47
Linus Tech Tips
Рет қаралды 570 М.
The Philosophy of Architecture - Barry O'Reilly - NDC Oslo 2024
43:54
NDC Conferences
Рет қаралды 10 М.
SEVEN things about API security - Philippe De Ryck - NDC Oslo 2024
55:36
NDC Conferences
Рет қаралды 3,4 М.
Chris Coyier: How to Think Like a Front-End Developer // Front Conference Zurich 2019
29:32
Security Insights: OpenStack and SCS
48:44
Sovereign Cloud Stack
Рет қаралды 43
How to fall in love with TDD - Gui Ferreira - NDC Oslo 2024
53:06
NDC Conferences
Рет қаралды 2,9 М.
Tag him😳💕 #miniphone #iphone #samsung #smartphone #fy
0:11
Pockify™
Рет қаралды 4,7 МЛН
تجربة أغرب توصيلة شحن ضد القطع تماما
0:56
صدام العزي
Рет қаралды 64 МЛН