3 ms·
The author kinda lost me halfway through. Was mobile or other non-web API interaction ever addressed in any meaningful way? Specifically, how much it sucks to t
by drspacemonkey 7y ago
The author kinda lost me halfway through. Was mobile or other non-web API interaction ever addressed in any meaningful way? Specifically, how much it sucks to to allow 3rd parties (or even 1st-party non-web-browser clients) access to your API if authentication is done via session cookies? Cuz that's a pretty significant thing to just gloss over.
- rdegges 7y agoThanks for the comment! I didn't cover that in this talk as it was written for a 1 hour timeslot and already ran long. I have separate content which addresses these topics in more depth.
- drspacemonkey 7y agoThanks, I look forward to reading it!
- kylequest 7y agoOAuth is a pretty popular option for delegation... and JWT isn't really necessary there...