7 ms·
Hard to believe this isn't common practice at this point. Way back when I was just getting started in my career I implemented an OAuth 2.0 server and it was alr
by peter_l_downs 3y ago
Hard to believe this isn't common practice at this point. Way back when I was just getting started in my career I implemented an OAuth 2.0 server and it was already accepted that auth code grants were the only reasonable way to do things. Here's what I wrote in the docs for that project:
The decisions that are most important to the security of your application are:
- The authorization endpoint will only return authorization codes, which can later be exchanged for access tokens.
- Password credentials grants, implicit grants, client credentials grants, and all extension grants are not supported.
- Public clients are not supported.
- Every client is required to register its redirect_uri.
- All authorization, token, and API requests are required to use TLS encryption in order to prevent credentials from being leaked to a third-party. In addition, the registered redirect_uri must also be secured with TLS.
- Clients are required to CSRF-protect their redirection endpoints.
https://djoauth2.readthedocs.io/en/latest/overview.html#what-is-implemented https://djoauth2.readthedocs.io/en/latest/overview.html#what...
- ranting-moth 3y agoAs for the "hard to believe", consider this: The guys who implemented this in the flawed way are probably at least twice as productive as the guys who'd thoroughly read the task and implement it correctly.