3 ms·
No, this is not how OAuth works - OAuth itself is just a protocol to receive authorization from another server [1]. In this case, a third party relies on Facebo
by fdw 9y ago
No, this is not how OAuth works - OAuth itself is just a protocol to receive authorization from another server [1]. In this case, a third party relies on Facebook to say "This user has logged into Facebook and their ID is foo". OAuth _does not need_ social information or anything else.
Of course, you can allow the authorization server to publish these details, but this is not an inherent part of OAuth. Also, there's OpenID Connect [2] which builds on OAuth and adds just this information in another token: "The ID token resembles the concept of an identity card, in a standard JWT format." (from [2]). However, you can happily use OAuth without ever publishing the user's details.
[1] https://tools.ietf.org/html/rfc6749 https://tools.ietf.org/html/rfc6749
[2] https://openid.net/connect/ https://openid.net/connect/
- darawk 9y agoYes, but my point is that the permission grant is explicit.
- olleromam91 9y agoWe (the general public) grant permission for facebook to use our data, with the expectation that they don't let any bad actors do anything with it that harms us (the general public). This has been their image, this is what they espouse, and it is clearly not what happened.
- fdw 9y agoYes, it is explicit. I took your comment to say "You have to allow access to your data if you're using OAuth, because that's how OAuth works", and wanted to argue against that. The OAuth protocol is so complicated because it tries to be safe and secure and so it doesn't force any data disclosure. However, I now see that you probably meant "OAuth forces you to accept these permissions explicitely". In that case, we're hopefully both right :)