3 ms·
That may have been the intent, but in a (very, very) large portion of cases the developer simply wants a way to verify identity claims. That is, verify that yo
by crashedsnow 11y ago
That may have been the intent, but in a (very, very) large portion of cases the developer simply wants a way to verify identity claims. That is, verify that you are who you claim to be. 3rd party identity providers (Facebook et. al.) are a convenient way to do this, for both the user and the developer (maintaining your own passwords is a pain etc). It's coincidence that these providers choose oAuth for this, but you still end up with oAuth for identity, not auth'z.
- dvanduzer 11y agoThe phrase "verify identity claims" just means "authorize". There has never been a version of OAuth that would authenticate an identity. edit: Sorry, it's easy to understand how "verify identity claim" does sound like authentication. What it means for OAuth, is that a system authorizes access based on delegated authentication. So "verifying an identity claim" is binding a local authorization event to a remote authentication event. Or something.