Introduction to OAuth 2.0 and OpenID Connect • Philippe De Ryck • GOTO 2018

Ғылым және технология

This presentation was recorded at GOTO Berlin 2018. #gotocon #gotober
gotober.com
Philippe De Ryck - Founder of Pragmatic Web Security, Google Developer Expert
ABSTRACT
OAuth is a delegation framework that appears on the radar of security professionals and developers more and more every day. OAuth intersects with authentication and access control, yet you would not likely use OAuth in and of itself for authentication, session management or an access control in your applications. Even more confusing, OAuth is not a standard and various service providers will likely have different implementations. Let's say it again, OAuth is not a standard - its a framework for delegation. So this leaves us with questions! What really is delegation? Where does OAuth fit [...]
Download slides and read the full abstract here:
gotober.com/2018/sessions/653
RECOMMENDED BOOKS
Aaron Parecki • OAuth 2.0 Simplified • amzn.to/2A3IMOf
Aaron Parecki • OAuth 2.0 Servers • amzn.to/3ecHEsz
Aaron Parecki • The Little Book of OAuth 2.0 RFCs • amzn.to/3i7qnlC
Erdal Ozkaya • Cybersecurity: The Beginner's Guide • amzn.to/2T6OIj3
Richer & Sanso • OAuth 2 in Action • amzn.to/3hXiAH6
Wilson & Hingnikar • Demystifying OAuth 2.0, OpenID Connect, and SAML 2.0 • amzn.to/2U8iLY2
/ gotober
/ gotoconference
/ goto-
gotocon.com
#OAuth2 #OAuth #OpenIDConnect #security #openID
Looking for a unique learning experience?
Attend the next GOTO Conference near you! Get your ticket at gotocon.com
SUBSCRIBE TO OUR CHANNEL - new videos posted almost daily.
kzread.info...

Пікірлер: 36

  • @leo-phiponacci
    @leo-phiponacci5 ай бұрын

    The best talk about OAuth and OIDC ever watched

  • @PaulVanBladel
    @PaulVanBladel2 жыл бұрын

    Brilliant. There are just talks or there is a presentation driven by someone who has the vast intention and willingness to transfer knowledge. That's what we have here. Thanks Philippe.

  • @vadimemelin2941
    @vadimemelin29412 жыл бұрын

    Man, I am glad that thing finally makes sense to me

  • @ubaidullah3328
    @ubaidullah3328 Жыл бұрын

    Thank you. First talk in two weeks that has explained oidc

  • @nikolassepos1640
    @nikolassepos16403 жыл бұрын

    Thank you Philippe De Ryck for this excellent presentation!

  • @islamh6042
    @islamh6042 Жыл бұрын

    A consolidated session. Thanks a lot Philippe and GOTO!

  • @VIJAYBVERMA
    @VIJAYBVERMA5 жыл бұрын

    Thank you. By far the best session on OAuth2.0 available on youtube.

  • @albpace
    @albpace5 жыл бұрын

    Finally an outstanding presentation that also explain the resource server perspective. Without doubt the best Oauth-2 presentation so far I have found on youtube.

  • @divabanyuwigara3562
    @divabanyuwigara35624 жыл бұрын

    I like this guy, he explain very well.

  • @sudiptapal7606
    @sudiptapal76064 жыл бұрын

    The best on the topic ! Philipe rocks !

  • @maartenknf
    @maartenknf2 жыл бұрын

    This is a really clear explanation!

  • @bipinkhatiwada
    @bipinkhatiwada5 жыл бұрын

    that's a very great explanation, man. thanks a lot.

  • @TanujitChowdhury
    @TanujitChowdhury4 жыл бұрын

    Really nice explanation on OIDC flow and what to do with the ID token

  • @maycon475
    @maycon4754 жыл бұрын

    Awesome explanation thanks Philippe

  • @mgrycz
    @mgrycz4 жыл бұрын

    Perfect presentation.

  • @iammen7
    @iammen74 жыл бұрын

    Very good explanation. Thanks you.

  • @baolam4180
    @baolam4180 Жыл бұрын

    Thanks

  • @Anon-tt9rz
    @Anon-tt9rz5 жыл бұрын

    very well presented, thanks!

  • @toriaezunama
    @toriaezunama5 жыл бұрын

    Really well explained. Thank you!

  • @loginjones
    @loginjones5 жыл бұрын

    wonderful talk

  • @daoudacamara5232
    @daoudacamara52325 жыл бұрын

    Very good presentation!

  • @tibi536
    @tibi5364 жыл бұрын

    Outstanding presentation, thank you for sharing!

  • @nikitarungta3423
    @nikitarungta34235 жыл бұрын

    very well explained

  • @jinxblaze
    @jinxblaze5 жыл бұрын

    beautiful

  • @acsidaho
    @acsidaho5 жыл бұрын

    very helpful. thank you.

  • @ThePelcher
    @ThePelcher5 жыл бұрын

    Very good!

  • @MrOsefosef
    @MrOsefosef Жыл бұрын

    Small but important detail 41:16 he says there are only 3 flows but in reality OpenID Connect supports all OAuth 2.0 grant types including ROPC Grant and Client Credentials Grant.

  • @rodolfopicoreti8115
    @rodolfopicoreti81154 жыл бұрын

    Excelent...

  • @nullentrophy
    @nullentrophy2 жыл бұрын

    I love GOTO; Intro

  • @tiwarivikash12
    @tiwarivikash124 жыл бұрын

    Endpoint should be /token instead of /auth at 17:26

  • @sarinnawangkanai7768
    @sarinnawangkanai7768 Жыл бұрын

    Philippe De Ryck

  • @tech.talk69
    @tech.talk694 жыл бұрын

    Can you give me that What is Client at 14 : 25 ?? Follow me it can Server API ?

  • @vincentbaeten173
    @vincentbaeten1734 жыл бұрын

    Too bad he doesn't say anything about the Authorization Code Grant with Proof Key For Code Exchange (PKCE) flow because that is now the recommended flow for public clients instead of the implicit flow. And yes this was recommended before 2018.

  • @ankitsolomon
    @ankitsolomon5 жыл бұрын

    Slides link pls

  • @GOTO-

    @GOTO-

    5 жыл бұрын

    Hi there, thanks for your comment. If available the slides are linked in the video description. Here you go: gotober.com/2018/sessions/653

Келесі