5 ms·
I'm curious why we are still messing around with all these tokens when we could be using asymmetric encryption, like Apple is using for their AppStore connect A
by bouk 6y ago
I'm curious why we are still messing around with all these tokens when we could be using asymmetric encryption, like Apple is using for their AppStore connect API https://developer.apple.com/documentation/appstoreconnectapi/generating_tokens_for_api_requests https://developer.apple.com/documentation/appstoreconnectapi...
Just seems fundamentally more secure.
- hurricaneSlider 6y agoFor scenarios where third party clients clients require delegated access to users, you can combine these two approaches, giving you the best of both worlds. For example we have configured our implementation of OpenID Connect to use PKCE for retrieving an authorization code, and then when calling the token endpoint, requires that the the client authenticate using a client_assertion JWT (as detailed in https://tools.ietf.org/html/rfc7523#section-2.2 https://tools.ietf.org/html/rfc7523#section-2.2)