4 ms·
The main confusion probably comes from the name Oauth, which seems to suggest that it is about Single Sign On/authentication, while in reality it's about granti
by ratiolat 6y ago
The main confusion probably comes from the name Oauth, which seems to suggest that it is about Single Sign On/authentication, while in reality it's about granting site A access to your data at site B.
- patmorgan23 6y agoThat's what Oauth is though. Oauth is NOT a single sign-on technology, it's about granting access to data across services. OpenID is a single sign-on protocol built on top of Oauth.
- sjroot 6y ago> That’s what Oauth is though. Splitting hairs but no, Oauth has nothing to do with authentication. An introductory article like this should address the distinction between authentication and authorization in the first section IMO.
- tasogare 6y ago> the distinction between authentication and authorization Distinction which is totally useless in practice as you certainly won’t have authorization without authentication.
- sjroot 6y agoSomewhat. One key “feature” of OAuth is that it completely omits the authentication process.
- caseysoftware 6y agoThe distinction is irrelevant if you just consider that authorization (authZ) always happens after authentication (authN) but it is important when you realize that different components/systems/protocols might be used in each. At that point, the separation is more about capabilities/responsibilities than "does it happen?" (This is what I do in my day job.)
- patmorgan23 6y agoWas my comment unclear? "Oauth is NOT single sign-on" single sign-on = authentication. "sharing data across services" = authorizing your data from service A to be used in service B.
- WGH_ 6y ago> OpenID is a single sign-on protocol built on top of Oauth. Note that there's older OpenID (without "Connect"), which, to my knowledge, is more or less dead nowadays, and OpenID Connect, which is indeed built on top of OAuth. Both are indeed SSO, though.
- the_arun 6y agoOAuth is for authorization. OAuth scope defines the permissions. Authentication is outside OAuth