Thanks, it did not.
OAuth and OpenID Connect are a denial of service attack on the brains of the humans who have to work with them.
Thanks, it did not.
OAuth and OpenID Connect are a denial of service attack on the brains of the humans who have to work with them.
How can B be sure that C is acting on A's behalf? Can A only allow C to access certain data (or send only certain data) in order to reduce risk?
A protocol that allows for that three way negotiation is OAuth.
Like with most specs, a lot of the complexity is added in the later years, by companies that have thousands of users and complex edge cases and necessities, and they are the ones dominating the council, and their needs are the ones that push forward newer versions.
So with most specs, the best way to start learning it is by learning from the oldest specs to the newest ones, so if you start by reading or using OAuth2, you will be bombarded with a lot of extra complexities, not even the current experts started like that.
If you need to catch up, always start with the oldest specs/versions.
So thanks!
I'll start reading the oldest HTTP spec for funzies.
Fwiw it's entirely possible to build a web server by listening on port 80 and reading the text stream and writing to the output stream, no libraries no frameworks no apache no ngninx. And I don't mean you need to rebuild a general purpose an apache like server, maybe for a landing page you can just serve a static page and you will be implementing a very small subset of HTTP.
> Fwiw it's entirely possible to build a web server by listening on port 80 and reading the text stream and writing to the output stream
Sounds like a fun weekend project.
Meanwhile https://www.couchbase.com/blog/wp-content/uploads/2021/05/oa...
The diagram on Microsoft's page[1] for that exact same scenario/flow is much clearer IMHO.
[1]: https://learn.microsoft.com/en-us/entra/identity-platform/v2...
The first diagram is literally all over, with just small labels to remind you that this box over here relates to that box over there.
The Microsoft diagram clearly show the parties involved, who they communicate with and in which sequence.
As I mentioned in another post, I found the MS pages very helpful to understand OAuth 2.0, and the clear diagrams was a large part of that.
I do not understand what I am doing and trust the docs, but it has never been a particularly difficult setup.
I would argue that then you do not "have to work with them", you are merely using products built with them.
The PGP packet has entered the chat.