2 ms·
nope, oAuth 2 is still a pain to use. all of the oAuths are developer hostile, they make authentication a many step process with many potential fail cases.
by peterbraden 15y ago
nope, oAuth 2 is still a pain to use. all of the oAuths are developer hostile, they make authentication a many step process with many potential fail cases.
- alexbilbie 15y agoOAuth 2 a simple two step process: 1) Redirect the user 2) Do a POST request to acquire an access token How is that a pain?
- pjscott 15y agoAnd to be pedantic, there's a third step: 3) When you make an authenticated API call, send the access token along with the request, and make sure you're using HTTPS. The HTTPS part is important to give a bunch of the security guarantees than OAuth 1 gives you with plain HTTP and some complicated crypto dancing around.
- andrewmccall 15y agoThe problem with OAuth1 was that the complicated crypto dancing around was exactly that, complicated. Making sure you're using HTTPS is hardly a big ask for developers on either the client or the server and frankly is probably a much better idea given most of these services are more likely than not sending some form of private data.