Justin Richer on OAuth

Gavin Henry · IEEE Software · 2019

In Episode 376 of “Software Engineering Radio,” Justin Richer, lead author of OAuth2 in Action and editor of OAuth extensions RFC 7591, 7592, and 7662, discusses the key technical features of the OAuth 2.0 protocol for authorization. Gavin Henry spoke with Richer about browser-based OAuth2, types of tokens, OpenID Connect, PKCE, JavaScript Object Notation Web Token pros and cons, where to store them, client secrets, single-page apps, mobile apps, current best practices, OAuth.XYZ, HEART, MITREid, token validation, dynamic client registration, the decision factors of the various types of authorization grants to use, and what is next for OAuth. To hear the full interview, visit http://www.se-radio.net or access our archives via RSS at http:// feeds.feedburner.com/se-radio.

Read the paper · More papers on PaperTik