Everything You Ever Wanted to Know About OAuth and OIDC

  Рет қаралды 41,552

OktaDev

OktaDev

Күн бұрын

Пікірлер: 35
@yapayzeka
@yapayzeka Жыл бұрын
I watched a lot of videos about the context and this is the most clear and satifying explanation of them all. thank you very very much.
@similityjoe
@similityjoe Ай бұрын
The best explained video I've seen so far! I love the analogies and examples, makes it easier to digest these hard concepts 👍👍
@xdaniel3936
@xdaniel3936 Жыл бұрын
This is by far the best explanation. Thank you so much!
@marcom.
@marcom. Жыл бұрын
Thanks a lot, Aaron. This is by far the best and comprehensive video I saw about these topics.
@soumyagupta4910
@soumyagupta4910 6 ай бұрын
didn't think I'd enjoy learning about OAuth so much. Thanks a ton!
@Shukla-ji_knp
@Shukla-ji_knp 3 ай бұрын
Give that person a Raise 🎉🎉 Just 6 min of the video and I feel more confident on Oauth vs OIDC 5:52
@jagan4269
@jagan4269 3 жыл бұрын
Wow!!! This is SPOT ON. Thanks for the excellent presentation Aaron.
@floid33556
@floid33556 Жыл бұрын
Really great explanation. Thank you!
@interdechile
@interdechile 2 жыл бұрын
Thanks Aaron! This is the clearest explanation about oauth that I have seen
@danchisholm1
@danchisholm1 4 ай бұрын
WOW truly excellent tutorial. good examples and description. surprising that it’s from a company who don’t always do so well on tutorial. thanks okta guys!!
@chrislegaxy6355
@chrislegaxy6355 3 жыл бұрын
By far the best explanation! 🙌 Thank you! You rock!
@emiliocolombo142
@emiliocolombo142 8 ай бұрын
Great high level overview of these protocols. Thank you a lot
@codeflip1227
@codeflip1227 2 жыл бұрын
Fantastic video, thank you. In fact the only explanation of these concepts I could find that made sense.
@AshenafiDemisse
@AshenafiDemisse 3 ай бұрын
Cross domain post requests or in general Cross origin requests (CORS) were not having much support in older browsers as you said. Particularly browsers older than Internet Explorer 10 do not support CORS requests.
@gitahinganga3136
@gitahinganga3136 2 жыл бұрын
Very clear and concise Thanks a bunch!
@martijn1967b1
@martijn1967b1 3 ай бұрын
Thanks Aaron
@leminhdung1981
@leminhdung1981 2 жыл бұрын
Excellent! Thank you very much!
@shaunpx1
@shaunpx1 2 жыл бұрын
Great video, thank you for clearly explaining this topic!!! Also Where did you get that shirt it is awesome!
@cli2701
@cli2701 3 жыл бұрын
Excellently explained! Thanks!
@meepk633
@meepk633 Жыл бұрын
So I should be using PKCE for my confidential OIDC client that's already checking state and nonce? I'd rather not rewrite it if those older DPOPs are sufficient.
@aaronpk
@aaronpk Жыл бұрын
If you are checking the nonce, as well as checking the ath claim in the ID token to compare it to the access token, then you are protected from access token injection. However there is no protection from ID token leakage in the front channel if you are using the OIDC implicit flow. The other way to look at it is you can remove a bunch of code and replace it with a smaller amount of code that does PKCE, and removing code means less opportunity for bugs and errors.
@kevincornally8392
@kevincornally8392 3 жыл бұрын
Such a great presentation !!!!
@li.tan.activities
@li.tan.activities 3 жыл бұрын
Fantastic explanation! Thank you!
@masteredd
@masteredd 3 жыл бұрын
Great explanation! Thanks
@gobindrawat3496
@gobindrawat3496 3 жыл бұрын
One more question : As mentioned in the use case , if the Access Token has 8 hours validity and during the registration/login , user gave consent for some explicit scopes ( example vehicle data) , the access token has the claims information and if clients are checking the claims information and validity against IDP token introspection endpoint and based on the response are letting the user uses their api. What if in the meantime , user revoke some of the consent ? Access Token will still consist the previously given consent information and if the client is based on IDP token introspection response then critical service access will become accessible. Revoking the token and asking the user to log in again so correct consent based token can be generated can lead to very bad user experience if IDP has global logout & SSO . Any best practices here ? Please share some . Thanx
@gobindrawat3496
@gobindrawat3496 3 жыл бұрын
Hi , I have a question regarding Refresh Token Use case especially when we have a unreliable clients ( Native Apps) . The new best practice about Refresh Token mentions that it should be replaced with each new token exchange request . So basically with new token exchange request , client receives a new refresh Token along with Access & ID Token . How should we tackle a Logout scenario if client is mobile app . Mobile App can have very unreliable network and due to this User can be logout due to expired Token . Is there any best practices regarding this use case ? Thanks I’m advance . Ok
@drakezen
@drakezen 3 жыл бұрын
Amazing explanation.
@debkr
@debkr 2 жыл бұрын
Nice 👍 Please post some videos on OIDC Single Sign on.
@4ortson
@4ortson 8 ай бұрын
this should be watched by more devs
@jamesallen74
@jamesallen74 3 жыл бұрын
Fantastic video!
@ftlight2362
@ftlight2362 3 жыл бұрын
that is soooo useful! ) great explanation, thanks!
@clz230
@clz230 3 жыл бұрын
It was nicely done, Aaron! Excellent presentation and effortless communication!
@cd-stephen
@cd-stephen Жыл бұрын
ftw
@cmkjfnve
@cmkjfnve 3 ай бұрын
can't follow without setting the speed to 0.75. 🙂 Can't understand what the rush is.
@nestorguemez4846
@nestorguemez4846 2 жыл бұрын
Excellent content!
OAuth 2.0 and OpenID Connect (in plain English)
1:02:17
OktaDev
Рет қаралды 1,8 МЛН
A Developer's Guide to SAML
27:47
OktaDev
Рет қаралды 196 М.
Tuna 🍣 ​⁠@patrickzeinali ​⁠@ChefRush
00:48
albert_cancook
Рет қаралды 148 МЛН
小丑女COCO的审判。#天使 #小丑 #超人不会飞
00:53
超人不会飞
Рет қаралды 16 МЛН
Мясо вегана? 🧐 @Whatthefshow
01:01
История одного вокалиста
Рет қаралды 7 МЛН
1% vs 100% #beatbox #tiktok
01:10
BeatboxJCOP
Рет қаралды 67 МЛН
Want to Succeed in Business? WATCH THIS Entrepreneurship vs Running a Business
5:39
Session Vs JWT: The Differences You May Not Know!
7:00
ByteByteGo
Рет қаралды 340 М.
How to Hack OAuth
25:10
OktaDev
Рет қаралды 44 М.
Explain it to Me Like I’m 5: Oauth2 and OpenID
47:50
SpringDeveloper
Рет қаралды 72 М.
An Illustrated Guide to OAuth and OpenID Connect
16:36
OktaDev
Рет қаралды 637 М.
Tuna 🍣 ​⁠@patrickzeinali ​⁠@ChefRush
00:48
albert_cancook
Рет қаралды 148 МЛН