OAuth: When Things Go Wrong

  Рет қаралды 26,959

OktaDev

OktaDev

Күн бұрын

Пікірлер: 13
@AidPast
@AidPast Жыл бұрын
EXCELLENT preso. Every product security engineer should watch this!
@KDOERAK
@KDOERAK 4 жыл бұрын
I learned a lot by watching this video; my time was well spent - thx!
@luismesquita6528
@luismesquita6528 2 жыл бұрын
Wow such a cool presentation, many thanks. The best way to have a deeper knowlodge on a concept is when we understand it's points of failure (although most are already solved).
@PriyankMandavawala
@PriyankMandavawala 4 жыл бұрын
This is a great video! very nicely explained!
@learnprogramming123
@learnprogramming123 6 жыл бұрын
Nice video. Thanks for uploading.
@aroundthisprettyplanet
@aroundthisprettyplanet 4 жыл бұрын
Nice presentation!
@-q-b0_1
@-q-b0_1 6 жыл бұрын
This is awesome
@SoeaOu
@SoeaOu 4 жыл бұрын
Great talk, thanks.
@debabhishek
@debabhishek 4 жыл бұрын
one question. I understand that we don't have an publicly accessible ip when we are connected to internet and browsing ,, how the front token is passed is it passed as http forward response with the token ?
@aaronpk
@aaronpk 4 жыл бұрын
The server sending data (the authorization server) sends back an HTTP redirect to the browser with the data it's trying to send back to the client. That HTTP redirect step is what we call the front channel.
@debabhishek
@debabhishek 4 жыл бұрын
@@aaronpk I have seen your another video and I understood how it works, but I am happy that you given enough attention to viewers queries , thanks again.
@nicolasduboc
@nicolasduboc 6 жыл бұрын
Very nice presentation, thanks. Could you elaborate a bit more on the last topic on the video regarding the validation of the access token by the protected resource server ? You seem to suggest that, in pure OAuth2 (not OIDC) this can be done by an additional endpoint out of scope of the OAuth2 spec. Then, doesn't that imply that there must be a strong compatibility relation between the auth server and the resource server ? For OpenId Connect, do you suggest that the client app can forward the IDToken, that it got for its own use, to the resource server app ? Isn't the IDToken audience only for the client app ?
Everything You Ever Wanted to Know About OAuth and OIDC
33:21
Securing Your APIs with OAuth 2.0 - API Days
31:36
OktaDev
Рет қаралды 71 М.
Quando eu quero Sushi (sem desperdiçar) 🍣
00:26
Los Wagners
Рет қаралды 15 МЛН
Don’t Choose The Wrong Box 😱
00:41
Topper Guild
Рет қаралды 62 МЛН
An Illustrated Guide to OAuth and OpenID Connect
16:36
OktaDev
Рет қаралды 637 М.
What's going on with the OAuth 2.0 Implicit flow?
17:18
OktaDev
Рет қаралды 86 М.
How to Hack OAuth
25:10
OktaDev
Рет қаралды 44 М.
Protecting Your APIs with OAuth
59:25
OktaDev
Рет қаралды 13 М.
Authentication as a Microservice
50:26
Oracle Developers
Рет қаралды 218 М.
Explain it to Me Like I’m 5: Oauth2 and OpenID
47:50
SpringDeveloper
Рет қаралды 72 М.
OAuth 2.0 and OpenID Connect (in plain English)
1:02:17
OktaDev
Рет қаралды 1,8 МЛН
What is JWT? JSON Web Tokens Explained (Java Brains)
14:53
Java Brains
Рет қаралды 1 МЛН
Quando eu quero Sushi (sem desperdiçar) 🍣
00:26
Los Wagners
Рет қаралды 15 МЛН