5 ms·
I would be very interested to see an implementation that doesn't. And I'm not being sarcastic. Even the device flow has you open a browser on another device.
by anderspitman 3y ago
I would be very interested to see an implementation that doesn't. And I'm not being sarcastic. Even the device flow has you open a browser on another device.
- pugz 3y agoI guess it depends on what we meant when we talk about OIDC, but in system-to-system authentication (e.g. GitHub Actions to ${cloud provider}), there are no browsers involved. But that's a fairly different use-case that happens to be under the OIDC umbrella. https://docs.github.com/en/actions/deployment/security-hardening-your-deployments/about-security-hardening-with-openid-connect https://docs.github.com/en/actions/deployment/security-harde...
- fireflash38 3y agoBasically just resource owner/password flow. Because clearly programmers don't know how to handle sensitive information, only browsers can.