3 ms·
I don't understand what's the point of this. So there is an answer that doesn't answer the question in SO, and we glorify because it... is confirmation that yes
by chucke 3y ago
I don't understand what's the point of this. So there is an answer that doesn't answer the question in SO, and we glorify because it... is confirmation that yes, it's bad?
OpenID is a specific layer on top of OAuth2. It standardised claims for authentication, scopes it down to the 2 credentials flows it can care about, and that's core in a nutshell. It's complicated, but so is HTTP, which most people don't use directly anyway (and the same should be applied for OpenID, just use a blessed implementation, the OpenID foundation maintains a list of certified libraries you can rely on).