3 ms·
The articles say these sites were validating the tokens - as in checking signatures - so they were doing that properly. The issuer is another matter. Facebook
by caseysoftware 3y ago
The articles say these sites were validating the tokens - as in checking signatures - so they were doing that properly.
The issuer is another matter. Facebook or any other social provider is different than using AD. With AD, every customer would have a separate and distinct issuer related to their specific org and config. For social auth, there would be ONE issuer that everyone shares.