Introduction to OAuth 2.0 and OpenID Connect • Philippe De Ryck • GOTO 2018

  Рет қаралды 47,393

GOTO Conferences

GOTO Conferences

Күн бұрын

This presentation was recorded at GOTO Berlin 2018. #gotocon #gotober
gotober.com
Philippe De Ryck - Founder of Pragmatic Web Security, Google Developer Expert ‪@philippederyck2572‬
ABSTRACT
OAuth is a delegation framework that appears on the radar of security professionals and developers more and more every day. OAuth intersects with authentication and access control, yet you would not likely use OAuth in and of itself for authentication, session management or an access control in your applications. Even more confusing, OAuth is not a standard and various service providers will likely have different implementations. Let's say it again, OAuth is not a standard - its a framework for delegation. So this leaves us with questions! What really is delegation? Where does OAuth fit [...]
Download slides and read the full abstract here:
gotober.com/20...
RECOMMENDED BOOKS
Aaron Parecki • OAuth 2.0 Simplified • amzn.to/2A3IMOf
Aaron Parecki • OAuth 2.0 Servers • amzn.to/3ecHEsz
Aaron Parecki • The Little Book of OAuth 2.0 RFCs • amzn.to/3i7qnlC
Erdal Ozkaya • Cybersecurity: The Beginner's Guide • amzn.to/2T6OIj3
Richer & Sanso • OAuth 2 in Action • amzn.to/3hXiAH6
Wilson & Hingnikar • Demystifying OAuth 2.0, OpenID Connect, and SAML 2.0 • amzn.to/2U8iLY2
/ gotocon
/ goto-
/ goto_con
/ gotoconferences
#OAuth2 #OAuth #OpenIDConnect #security #openID #PhilippeDeRyck
CHANNEL MEMBERSHIP BONUS
Join this channel to get early access to videos & other perks:
/ @goto-
Looking for a unique learning experience?
Attend the next GOTO conference near you! Get your ticket at gotopia.tech
Sign up for updates and specials at gotopia.tech/n...
SUBSCRIBE TO OUR CHANNEL - new videos posted almost daily.
www.youtube.co...

Пікірлер: 37
@PaulVanBladel
@PaulVanBladel 3 жыл бұрын
Brilliant. There are just talks or there is a presentation driven by someone who has the vast intention and willingness to transfer knowledge. That's what we have here. Thanks Philippe.
@leo-phiponacci
@leo-phiponacci Жыл бұрын
The best talk about OAuth and OIDC ever watched
@vadimemelin2941
@vadimemelin2941 2 жыл бұрын
Man, I am glad that thing finally makes sense to me
@ubaidullah3328
@ubaidullah3328 2 жыл бұрын
Thank you. First talk in two weeks that has explained oidc
@albpace
@albpace 5 жыл бұрын
Finally an outstanding presentation that also explain the resource server perspective. Without doubt the best Oauth-2 presentation so far I have found on youtube.
@VIJAYBVERMA
@VIJAYBVERMA 5 жыл бұрын
Thank you. By far the best session on OAuth2.0 available on youtube.
@islamh6042
@islamh6042 2 жыл бұрын
A consolidated session. Thanks a lot Philippe and GOTO!
@nikolassepos1640
@nikolassepos1640 4 жыл бұрын
Thank you Philippe De Ryck for this excellent presentation!
@TanujitChowdhury
@TanujitChowdhury 4 жыл бұрын
Really nice explanation on OIDC flow and what to do with the ID token
@sudiptapal7606
@sudiptapal7606 5 жыл бұрын
The best on the topic ! Philipe rocks !
@maartenknf
@maartenknf 3 жыл бұрын
This is a really clear explanation!
@divabanyuwigara3562
@divabanyuwigara3562 5 жыл бұрын
I like this guy, he explain very well.
@jailson772
@jailson772 5 жыл бұрын
Awesome explanation thanks Philippe
@bipinkhatiwada
@bipinkhatiwada 5 жыл бұрын
that's a very great explanation, man. thanks a lot.
@MrOsefosef
@MrOsefosef 2 жыл бұрын
Small but important detail 41:16 he says there are only 3 flows but in reality OpenID Connect supports all OAuth 2.0 grant types including ROPC Grant and Client Credentials Grant.
@tibi536
@tibi536 5 жыл бұрын
Outstanding presentation, thank you for sharing!
@tiwarivikash12
@tiwarivikash12 5 жыл бұрын
Endpoint should be /token instead of /auth at 17:26
@iammen7
@iammen7 5 жыл бұрын
Very good explanation. Thanks you.
@hackerman5764
@hackerman5764 3 ай бұрын
In these diagrams, using the Twitter example, would "client" always refer to Buffer's back and and "resource server" always refer to Twitter's back end?
@mgrycz
@mgrycz 5 жыл бұрын
Perfect presentation.
@baolam4180
@baolam4180 2 жыл бұрын
Thanks
@nullentrophy
@nullentrophy 3 жыл бұрын
I love GOTO; Intro
@daoudacamara5232
@daoudacamara5232 5 жыл бұрын
Very good presentation!
@loginjones
@loginjones 6 жыл бұрын
wonderful talk
@toriaezunama
@toriaezunama 6 жыл бұрын
Really well explained. Thank you!
@Anon-tt9rz
@Anon-tt9rz 6 жыл бұрын
very well presented, thanks!
@jinxblaze
@jinxblaze 6 жыл бұрын
beautiful
@nikitarungta3423
@nikitarungta3423 6 жыл бұрын
very well explained
@acsidaho
@acsidaho 6 жыл бұрын
very helpful. thank you.
@ThePelcher
@ThePelcher 5 жыл бұрын
Very good!
@rodolfopicoreti8115
@rodolfopicoreti8115 5 жыл бұрын
Excelent...
@vincentbaeten173
@vincentbaeten173 4 жыл бұрын
Too bad he doesn't say anything about the Authorization Code Grant with Proof Key For Code Exchange (PKCE) flow because that is now the recommended flow for public clients instead of the implicit flow. And yes this was recommended before 2018.
@ankitsolomon
@ankitsolomon 6 жыл бұрын
Slides link pls
@GOTO-
@GOTO- 6 жыл бұрын
Hi there, thanks for your comment. If available the slides are linked in the video description. Here you go: gotober.com/2018/sessions/653
@tech.talk69
@tech.talk69 4 жыл бұрын
Can you give me that What is Client at 14 : 25 ?? Follow me it can Server API ?
@sarinnawangkanai7768
@sarinnawangkanai7768 2 жыл бұрын
Philippe De Ryck
OAuth 2.0 and OpenID Connect (in plain English)
1:02:17
OktaDev
Рет қаралды 1,8 МЛН
Mom Hack for Cooking Solo with a Little One! 🍳👶
00:15
5-Minute Crafts HOUSE
Рет қаралды 23 МЛН
Сестра обхитрила!
00:17
Victoria Portfolio
Рет қаралды 958 М.
Explain it to Me Like I’m 5: Oauth2 and OpenID
47:50
SpringDeveloper
Рет қаралды 72 М.
Functional Programming in 40 Minutes • Russ Olsen • GOTO 2018
41:35
GOTO Conferences
Рет қаралды 823 М.
Everything You Ever Wanted to Know About OAuth and OIDC
33:21
Mastering Chaos - A Netflix Guide to Microservices
53:14
InfoQ
Рет қаралды 2,3 МЛН
Cybersecurity Architecture: Who Are You? Identity and Access Management
31:15
OAuth 2.0 explained with examples
10:03
ByteMonk
Рет қаралды 186 М.
Mom Hack for Cooking Solo with a Little One! 🍳👶
00:15
5-Minute Crafts HOUSE
Рет қаралды 23 МЛН