Is redirect flow intrusive? - 2 min. OAuth #11

preview_player
Показать описание
Nat Sakimura, the chairman of the OpenID Foundation, explains various concepts of OAuth in 2 minutes per episode.

In this episode #11, he explains that people dislike "Redirect Flow" saying that it is intrusive, but that is not correct: It is just the bad implementation. He then explains how it works great using prompt parameter.

Subscribe to the channel to get (hopefully) Weekly video updates on "2 Minutes OAuth" and more.

Рекомендации по теме
Комментарии
Автор

Hi, I have struggled a lot to know about how to handle the authentication with mobile apps. Let me explain you my problem. I have my Identity provider with OpenID, but the mobile developers of my team (IOS/Android) want to use their login screen at level of the client in order to authenticate users with username and password. They do not want to be redirected because they consider it is a bad user experience and because it was defined in that way by UI designers. They want the same look and feel as Facebook app. Where you open the app you enter your username and password and you are done. Is there a way to achieve that in a secure way? without using password grant? How does FB login into his own server without leaving the login screen from his app? Thank you for your support. I'm glad I found this channel by accident

arturoescutialopez
welcome to shbcf.ru