4 ms·
unfortunately there are very few apps so far that allow signing in with apple even though i see them offer email, google and facebook options. i think out of a
by ir77 7y ago
unfortunately there are very few apps so far that allow signing in with apple even though i see them offer email, google and facebook options. i think out of all of the apps that i use only adobe lightroom allowed me to sign up with apple.
- m3kw9 7y agoBecause those app devs also wants to know more about you
- dave5104 7y agoIt will be mandatory to be on the app store at some point, so that won't be a valid excuse for app developers.
- K0nserv 7y agoAs I understand it Apple will make it mandatory for any app that offers social logins of any kind at some point.[0] Shameless plug, I work for Skyscanner and we've had it since iOS 13 launch. 0: https://www.macrumors.com/guide/sign-in-with-apple/ https://www.macrumors.com/guide/sign-in-with-apple/
- ascagnel_ 7y agoMy understanding is that "Sign in With Apple" is still officially in beta; once it launches in full, all iOS apps that offer third-party sign ins (like the Google & Facebook options) will be mandated to also offer Apple's OAuth sign-in -- and must give it more prominent placement than third-party services.
- snowron6 7y ago>will be mandated to also offer Apple's OAuth sign-in -- and must give it more prominent placement than third-party services. That seems like an abuse of monopoly power.
- frenchyatwork 7y agoWelcome to iOS development.
- mcphage 7y agoHow so?
- mikece 7y agoIs Sign in with Apple compliant with OAuth2 / OpenID Conenct? If it's not I don't see how Apple can justify mandating the inclusion of something that isn't standards-based?
- ascagnel_ 7y agoThey don't call it OAuth/OpenID, but they're using the same terminology and API: https://developer.okta.com/blog/2019/06/04/what-the-heck-is-sign-in-with-apple#how-sign-in-with-apple-works-hint-it-uses-oauth-and-oidc https://developer.okta.com/blog/2019/06/04/what-the-heck-is-...
- setr 7y agoIf they provide a sufficiently good sdk, I'm not clear on what the issue is justification-wise, beyond the justification necessary for any mandatory inclusions they already have. Why does a standard matter for justifying mandatory inclusion of ... anything? Most of their mandates probably lack any kind of standardization.
- TJSomething 7y agoIt's mostly compliant as of a few months ago [0]. That document is actually out of date, because Apple added a discovery endpoint since then [1]. They also haven't implemented the userinfo endpoint, but the only claims they expose are openid, name, and email, so it's not that big of a deal to just ask for those in the id_token. And the client_secret_post thing isn't much of a problem either, since their custom JWT is a perfectly valid client secret that's compliant with the underlying OAuth 2.0 standard and it's explained in their discovery document. [0] https://bitbucket.org/openid/connect/src/default/How-Sign-in-with-Apple-differs-from-OpenID-Connect.md https://bitbucket.org/openid/connect/src/default/How-Sign-in... [1] https://appleid.apple.com/.well-known/openid-configuration https://appleid.apple.com/.well-known/openid-configuration
- anentropic 7y agoafter March these apps will have to offer Apple sign-in or get booted from the app store...