5 ms·
Is OAuth2 back in the good graces of the dev community? I thought one of its creators considered it a dead standard? https://hueniverse.com/2012/07/26/oauth-2
by notdonspaulding 10y ago
Is OAuth2 back in the good graces of the dev community? I thought one of its creators considered it a dead standard?
https://hueniverse.com/2012/07/26/oauth-2-0-and-the-road-to-hell/ https://hueniverse.com/2012/07/26/oauth-2-0-and-the-road-to-...
(Genuinely asking because I've been thinking I might use a centralized auth store in a project recently and I wondered what the state of the art was.)
- arekkas 10y agoThat post is very popular, but there is a follow up posting on OpenID Connect and that it can makes sense. I have to dig that out though, couldn't find the link in my bookmarks.
- arekkas 10y agoalso noteworthy that the blog post is 4 years old and OAuth2 is basically everywhere :)
- paulddraper 10y agoAlso noteworthy that adoption doesn't change any of the points made.
- arekkas 10y agoadoption doesn't change the points semantically, but it shows that a large part of the (corporate) secrutiy community weighs those arguments (much) less than the author does.
- arekkas 10y agook, I finally found it. Note that it's still from 2012 and we've moved along from that dispute. * http://www.thread-safe.com/2012/07/the-oauth-2-sky-is-not-falling.html http://www.thread-safe.com/2012/07/the-oauth-2-sky-is-not-fa... * https://hueniverse.com/2012/07/30/on-leaving-oauth/ https://hueniverse.com/2012/07/30/on-leaving-oauth/
- supergeek133 10y agoGood graces? It's not perfect, mostly people over-granting permissions.. but in most cases you can't run into an API or other rights sharing tool without OAuth2.