ttumblr

  • Archive
  • RSS
the UMA bearer token profile and the UMA OpenID Connect claim profile
[WG-UMA] Fresh core spec draft is up: rev 05c

Source: kantarainitiative.org

    • #identity
  • 9 months ago
  • Permalink
Share

Short URL

TwitterFacebookPinterestGoogle+
The Google authorization server rejects all
redirect_uris that don't match registered values, and compares them
exactly. Adding a query parameter to a redirect_uri will cause Google
to invalidate the request. That's fully compatible with OAuth2. That's
why OAuth2 defines a state parameter. 
[Openid-specs-ab] Additional issues with redirect
    • #google
    • #oauth
    • #practice
    • #deployment
    • #security
    • #identity
    • #api
  • 1 year ago
  • Permalink
Share

Short URL

TwitterFacebookPinterestGoogle+
From a trust perspective, my contacts trust that I’ll use their info for the purpose it was given to me – e.g. for me to use in order to communicate with them.  They trust that I’m not handing it out to anyone or any thing that asks for it.
UnboundID Blog - Is Privacy a Contact Sport?
    • #privacy
    • #identity
    • #thought
  • 1 year ago
  • Permalink
Share

Short URL

TwitterFacebookPinterestGoogle+

Using OAuth 2.0 for Server to Server Applications - Google Accounts Authentication and Authorization — Google Developers

APIコンソールでサービスアカウント生成
Googleが鍵ペア生成
管理者が秘密鍵をダウンロード
Googleは秘密鍵を破棄し、公開鍵のみを保管

    • #google
    • #api
    • #jwt
    • #security
    • #identity
    • #oauth
    • #practice
    • #deployment
  • 1 year ago
  • Permalink
Share

Short URL

TwitterFacebookPinterestGoogle+

[Openid-specs-ab] YATVE (Yet Another Token Validation endpoint)

AOLのトークン検証エンドポイント仕様。JWTなATの署名などを検証後、そこに入ってるuidがRSにおいて連携済みかどうか確認。もし連携済みならATをAuthZ Svrに投げる。ASはATが有効ならuidのみを返す(性能的に有利)。UserInfo的な何かはPoCo

    • #identity
    • #oauth
    • #deployment
    • #practice
    • #openid
    • #specification
  • 1 year ago
  • 1
  • Permalink
Share

Short URL

TwitterFacebookPinterestGoogle+

Another interesting issue regarding the CDN is authorization. Ourcontent, and the tenants’ content, is not to be freely handed out. So,even though a given resource (for a given tennant) is cached at theCDN, it can’t just be handed over. The CDN is not wired in as aresource server checking out our token store etc., so it cannot dealwith the OAuth token itself. Both Akamai and Edgecast, for example,can be set up to forward requests to the origin server forauthorization. All information (method, URI, headers, params) are madeavailable, so just like any other request, I can verify the token andtenant ID, and indicate whether or not the CDN is to return the cacheobject (and perhaps update it with a new version) or not.

There is obvious overhead to this forwarding for authorization, but I don’t see another way around it.

Code abstraction for API in large projects - Google グループ CDNとOAuth
    • #oauth
    • #deployment
    • #practice
    • #identity
  • 1 year ago
  • Permalink
Share

Short URL

TwitterFacebookPinterestGoogle+
The AS->RS work is probably simpler and more useful at this point.

Re: [OAUTH-WG] OAuth WG Re-Chartering

リソースサーバーと認可サーバーとの間のトークン検証のやりとりの仕様策定が、今後の OAuth WG のお題に入りそうな感じ

    • #oauth
    • #specification
    • #identity
  • 1 year ago
  • 1
  • Permalink
Share

Short URL

TwitterFacebookPinterestGoogle+

Getting Started with OAuth 2.0 > 7. OpenID Connect Authentication - Pg. 51: Safari Books Online

OAuth2 の本、 #OpenID Connect のことも書かれてるのか

    • #openid
    • #oauth
    • #identity
    • #tutorial
    • #reference
    • #specification
  • 1 year ago
  • Permalink
Share

Short URL

TwitterFacebookPinterestGoogle+
UMA_Venn.png

Venn of Authz draft 16 Feb 2012 @xmlgrrl
Pop-upView Separately

UMA_Venn.png

Venn of Authz draft 16 Feb 2012 @xmlgrrl

    • #identity
    • #oauth
    • #openid
    • #uma
  • 1 year ago
  • Permalink
Share

Short URL

TwitterFacebookPinterestGoogle+
Digital persona protection
Deloitte predicts the top 10 technology trends for 2012 | TechJournal South
    • #trend
    • #identity
    • #analysis
    • #market
    • #privacy
    • #assurance
    • #business
  • 1 year ago
  • Permalink
Share

Short URL

TwitterFacebookPinterestGoogle+
Page 1 of 15
← Newer • Older →

About

Twitter

loading tweets…

  • RSS
  • Random
  • Archive
  • Mobile
Effector Theme by Pixel Union