Sign In Start Free Trial
Account

Add to playlist

Create a Playlist

Modal Close icon
You need to login to use this feature.
  • Mastering OAuth 2.0
  • Toc
  • feedback
Mastering OAuth 2.0

Mastering OAuth 2.0

3.5 (6)
close
Mastering OAuth 2.0

Mastering OAuth 2.0

3.5 (6)

Overview of this book

OAuth 2.0 is a powerful authentication and authorization framework that has been adopted as a standard in the technical community. Proper use of this protocol will enable your application to interact with the world's most popular service providers, allowing you to leverage their world-class technologies in your own application. Want to log your user in to your application with their Facebook account? Want to display an interactive Google Map in your application? How about posting an update to your user's LinkedIn feed? This is all achievable through the power of OAuth. With a focus on practicality and security, this book takes a detailed and hands-on approach to explaining the protocol, highlighting important pieces of information along the way. At the beginning, you will learn what OAuth is, how it works at a high level, and the steps involved in creating an application. After obtaining an overview of OAuth, you will move on to the second part of the book where you will learn the need for and importance of registering your application and types of supported workflows. You will discover more about the access token, how you can use it with your application, and how to refresh it after expiration. By the end of the book, you will know how to make your application architecture robust. You will explore the security considerations and effective methods to debug your applications using appropriate tools. You will also have a look at special considerations to integrate with OAuth service providers via native mobile applications. In addition, you will also come across support resources for OAuth and credentials grant.
Table of Contents (17 chapters)
close
11
11. Tooling and Troubleshooting
16
Index

Refresher on the authorization code grant flow

Recall from Chapter 2, A Bird's Eye View of OAuth 2.0, the authorization code grant flow is the OAuth 2.0 flow used for trusted clients. These are typically web applications powered by some sort of backend. For example, an HTML/JS frontend powered by a Python server, or a Flash frontend powered by a Ruby on Rails backend. For our sample application, WMIIG, we will be building an HTML/JS frontend powered by a Java backend.

The addition of a server-side to the access token workflow makes the authorization code grant flow more secure and more powerful than the client-side implicit grant flow. We will see how as we proceed through this chapter. For now, recall that the authorization code grant flow looks like this:

Refresher on the authorization code grant flow

In the context of our application, WMIIG (World's Most Interesting Infographic Generator), the sequence of steps would be as follows:

  1. The user visits WMIIG and initiates the process to see the world's most interesting infographic...

Unlock full access

Continue reading for free

A Packt free trial gives you instant online access to our library of over 7000 practical eBooks and videos, constantly updated with the latest in tech
bookmark search playlist download font-size

Change the font size

margin-width

Change margin width

day-mode

Change background colour

Close icon Search
Country selected

Close icon Your notes and bookmarks

Delete Bookmark

Modal Close icon
Are you sure you want to delete it?
Cancel
Yes, Delete