HelloJS – Client-side OAuth for JS
adodson.com
adodson.com
As it requires an "OAuth proxy" for OAuth 1.0a and some implementations of OAuth 2.0, it seems that it offloads the crypto (and secret API key) to that proxy.
Google(+?) requires you to whitelist possible redirect URLs, meaning that it's much more obvious what happens after a redirect. Thus limiting what an attacker may do...
It's not it was more secure,it's that it is impossible to secure anything on the client(native or html,by the way) if there is no interaction with a server doing access control somehow. That one reason why old facebook app was downloading HTML instead of having it bundled and just requesting json payloads).
What is a single page app? a single HTML file.How can you secure anything in a single HTML file? there are no "pages", the browser history is just tricked into pushing or poping url states.
You can however decide that an API call will fetch resources like js and css right after a user is logged in,but that's the server doing its job,and the assets would be served either through tokenized temporary URLs , or read on the server's disk , streamed through a server-side language then dumped in the client.
I bet that a majority of SPAs out there dont do that,and sensitive assets are downloadable even when a user isnt logged in.
A non authorized user shouldnt have accessed to these assets,or even endpoint URLs meant for authorized users.But yeah,it means using a proper server-side language and not just serving everything from S3.
If your point is "nothing is secure in the browser" then that includes the secured content sent down by a secure server no matter the method.
I believe this is only possible since OAuth2. One important aspect is that the API provider registers the consumer's key along with their domain, so API requests using that key are only valid coming from that domain.
Thanks for sharing.
Does this mean in Facebook, Google etc the grant token and the access token are identical?
From my experience memory is safe between origins in the same way cookies are. And it is the dev's responsibility to not do something stupid with the token like window.FacebookToken = OAuthToken;. But that holds for traditional session cookies as well.
What is application in that sentence? The API?
Isn't that what this lib does?
A client-side Javascript SDK for authenticating with OAuth2 web services and querying their REST API's.
- I assume the API issues the token - This lib receives it and uses it for subsequent calls - The token is destroyed when browser session is closed.
I'm baffled this actually works. The entire idea is that the `client_id` can be disclosed to the user (via the login redirect) because the `client_secret` is required to verify the application's identity.
[1] http://nodejs.org/ [2] http://bower.io/
HelloJS = Browser + Phonegap authentication and API request handling designed to interact with thirdparty services from the client app.
I can think of a few other systems where it would be useful, but in general an application interface (including offline support) comes to mind here.
1. So this is 100% client side... Why do I see "npm" in the instructions? Isn't that connected to nodejs? What if I'm writing a java web server app, will this still work, or does it need to talk to a nodejs server somehow?
2. I take it none of this hits a third party server (i.e. your server)?
3. How do I get the user's info obtained via authentication (gmail address, etc) to my server, in a way that is secure, if this is all client & browser based?
Its on npm for convenience. I also hope to make it compatible with CommonJs and have components of it work through the server.
Not all services support server-less authentication otherwise known as Implicit OAuth2. As such, i've put a proxy service up on Heroku. Read up at http://adodson.com/hello.js/#oauth-proxy
2. I see no reason why it would.
3. It's all client based regardless of how you do it, it just adds cookies. If you want to get the information server side just get it server side (PHP example https://github.com/thephpleague/oauth2-client) there is no need to get it client side if you need it server side with a server side library (thus why NPM is shown as node is server side).
[1] http://bower.io/
There's more comments on this subject here https://github.com/MrSwitch/hello.js/issues/22
What could possibly go wrong? ;)