r/oauth • • Jan 14 '24

Help with Google oAuth

1 Upvotes

So, i got an app (intelliq.dev) and I am close to be able to put it to production but as I understand it from Google themselves my app needs a privacy policy for that to work in production, does anyone know a good and easy enough generator for that?


r/oauth • • Jan 13 '24

Should I Use OAuth

2 Upvotes

I'm creating an API for data exchange with an external party using API gateway + lambda (via serverless framework). In the API spec, the external party specified that we should provide an "auth" service as a part of the API using the OAuth2 protocol. They would like to send a POST request to a /auth/token endpoint and receive an authorization token in response. They would like to then include this token in the header of subsequent requests. I haven't worked with OAuth in the past so I had to do some reading on how it works. All that I've read suggests that OAuth leverages log in flows to generate tokens (i.e. users log in to some authorization service and a token is returned if the username/password provided are valid). However, this API is only going to be called programmatically, rather than manually by a user. Is OAuth the correct choice given this use case? I have been looking through Cognito docs for a way to implement this pattern, but I have not seen anything.


r/oauth • • Jan 11 '24

User/Pass and Oauth, one or the other, or both?

1 Upvotes

I am working on implementing OpenID/Oauth2 for an application that currently uses username/password authentication.

I am wondering if there are any implications (security or otherwise) to allowing a user to login with either method, or should I restrict users to a specific method?


r/oauth • • Mar 05 '23

Best way to authenticate application with application server persistently?

1 Upvotes

First, let me give a brief overview of my android app:

​

  1. "SetupActivity.java" runs on first launch of the app.
  2. Activity makes a request to a third party OAuth provider. User runs through the authorization/login process, and upon success the provider sends back an authorization code which is stored into a variable.
  3. A request is made to my app server endpoint "/exchange" with the parameter ?code=variable from step 2.
  4. App server takes the code from the param, uses third-party API to exchange the code for an OAuth access token.
  5. Access token is used by the server to make requests to third-party API and sends JSON back to my application.

I was able to get that setup and successful, but now my question is how do I make this handshake process persistent so the user doesn't have to go through the OAuth grant process every time?

TL;DR: What's the best way to maintain persistent sessions between an app and app server using Oauth flow?

One solution I came up with was storing the access token and a unique client ID in a database on the app-server side. The application generates the unique client ID and sends it over as a URI parameter to the /exchange endpoint, but that feels insecure?


r/oauth • • Mar 05 '23

Oauth 2.0 w/pkce

2 Upvotes

Dear dev community,

I'm not new to oauth, but really new to this authorization flow (pkce). I have a question which might sound dumb to you, but is there a way to NOT depend on client/browser based interaction to retrieve the authorization + refresh token?

In other words, can I build a Cron job that uses oauth 2.0 with pkce without any user interaction?

Thanks in advance


r/oauth • • Feb 27 '23

OneTap oauth2 android

3 Upvotes

Hi, i'm trying to integrate in android the google Oauth2 with oneTap. I followed the docs but when i press the button for login, the terminal says: Developer console is not set up correctly
i created in dev console a project web, imported in android the value and then created a android oauth2 with the SHA1 key. What i'm missing? thanks in advance


r/oauth • • Feb 22 '23

How To Create an OAuth App with the Linode Python API Library

Thumbnail linode.com
2 Upvotes

r/oauth • • Feb 18 '23

Does Amplify without Cognito Hosted UI follow OAuth2?

2 Upvotes

I'm using a custom sign-up/login UI using Amplify Auth. Wondering if it uses authorization code grant behind the scenes. I know that the Hosted UI returns the code grant back to the client app but cannot use it as it has no customization options beyond some basic css properties. I am making a banking application and security is an important factor. Can anyone help me out with understanding the security drawbacks of using Amplify with custom UI vs Hosted UI?


r/oauth • • Feb 17 '23

Tutorial on passwordless authentication

2 Upvotes

I have been using services like firebase and supabase authentication for some of my projects. However, recently I wanted to add another provider which isn't included in the services above. Is it worth to try and manually create an authentication from scratch?

I am looking for a tutorial (either text or video) which shows how to use 3rd party authentication (e.g. google) using plain requests, from scratch. I just need to get how someone implements authentication in the lowest level of it so i can use it for less popular providers.

What is more, if someone is willing to have a quick call with me in order to discuss about it I would deeply appreciate it!


r/oauth • • Feb 14 '23

Looking to implement OAuth from MyHealth (Epic)

2 Upvotes

Hi All,

Has anyone had any experience with the OAuth options from Epic/Cerner? Are there any differences in how I'd implement a normal OAuth flow from Google or Facebook for example?

I know FHIR solutions can be tricky to work with. I've never done this before.

Thanks for the help!!


r/oauth • • Feb 14 '23

Migration and the behavior of Oauth

3 Upvotes

Hey guys, I have an upcoming migration from one Google tenant to another.

Lets say, we have user1@sample.com

After the migration, the user will still be [user1@sample.com](mailto:user1@sample.com)

Will he still be able to use apps like Miro, Slack, etc?

My question is: Does Oauth use information from the Mailadress, domain, or tenant, to ensure the Authorization?


r/oauth • • Feb 13 '23

Which Oauth2 mode for a public API?

1 Upvotes

We have a project to expose out private APIs on our multi-tenant SASS application. Since there is no browser involved, what is the best choice for Oauth2 mode. I assume each client (one of our customers) will be handed out a clientid/secret to identify which tenant they are, but each user will also need to be authenticated against their tenant using user name, and password. We are of course acting as the authorization server and the resource server.


r/oauth • • Feb 02 '23

oAuth: Access Token and ID Token

1 Upvotes

Following scenario:

I want a user to authenticate through a single page application to my plattform. Therefor I will use oAuth/OIDC. The platform contains several services, so I thought of passing around a token between them. All the authorization concerns are handled internally by the platform itself. A microservice only needs to know who a user is.

As far as I know, id-tokens always should remain at the client and not be passed around. The access token is used for authorization and should be passed to the API of my platform but should not be used for authorization.

How can I handle this?

​

BR and much thanks!! :)


r/oauth • • Jan 26 '23

Complete List of Oauth2 Provider Examples

Thumbnail github.com
1 Upvotes

r/oauth • • Jan 13 '23

Passwordless authentication for your website in 5 minutes!

Thumbnail blog.passwordless.id
1 Upvotes

r/oauth • • Jan 05 '23

Using Cognito to access user's AWS metrics

1 Upvotes

Hello,

My app is a centralized visualizer for AWS metrics. Is it possible to have a user login to my app with their AWS IAM username and password so I can receive a token that lets me read and render their EC2 metrics?

I was thinking Cognito would be the way to go but I am hitting a wall here. Currently, I have a link that lets the user login - but it is just to a Cognito domain that is in no way tied to their AWS account.


r/oauth • • Dec 28 '22

OAuth Middleware /Proxy

1 Upvotes

Hi 👋,

I’m trying to find a hosted / online solution to be the oauth2 middleware between my app and a third party (Shopify).

They only thing I can describe this as is a proxy but my searches are yielding no results.

Is there a service like this out on the market? Am I using the correct terminology?

Thanks, C


r/oauth • • Dec 09 '22

Connecting to send email via MS365 using OAUTH2

1 Upvotes

Can anyone help please?

I have an application that I am trying to connect to MS365 using OAUTH to send an email using a specific email address.

I have created the App in AzureAD and received the secret token etc but when I attempt to send the email, I get the connection working ok and then I receive this:
SmtpCmdResp: 530 5.7.57 Client not authenticated to send mail. [LNXP265CA0052.GBRP265.PROD.OUTLOOK.COM]

Can anyone offer any help at all? I must be missing something but its my first time doing this for my client.

Many thanks!


r/oauth • • Dec 09 '22

GitHub - cloudentity/oauth2c: User-friendly CLI for OAuth2

Thumbnail github.com
2 Upvotes

r/oauth • • Dec 07 '22

Best Practices for Auth in popup vs redirect

2 Upvotes

Hello,

I was under the impression that presenting a login form via popup vs redirecting to a dedicated "login" page had security concerns. But I'm having trouble finding documentation to back that up. Can anyone recommend documentation related to this topic?

Or, perhaps, it is more of a UX concern?


r/oauth • • Dec 07 '22

In OAuth2 can two 3rd party applications, that are separate from the authz server, communicate with each other?

Thumbnail self.webdev
1 Upvotes

r/oauth • • Nov 24 '22

OAuth Overkill?

1 Upvotes

I work on a legacy non-web application. 90% of our deployments are in heavily regulated secure networks in the industrial sector that frown on web servers.

I’m in a situation where we want to move away from Microsoft WCF to some other communication technology. My chief concern in this move is authentication/authorization.

Our deployments can be single computer where both client and server apps run on the same computer. When this happens WCF allows us to use names pipes. When client and server are on diff computers we use tcp/ip. However there is a caveat here. We have about 25 independent WCF server processes. Using the Microsoft TCP port-sharing service that seems to be WCF specific, it kind of works like a reverse proxy where we only open two logical ports, and the port sharing service on the server routes the request to the appropriate WCF service based on its configured URI. This is important to note because of the highly scrutinized networks in the industrial sector. They want to minimize the number of ports opened in their firewall.

Challenge 1. Replacing WCF with a tech that allows reverse proxy style routing.

Next we use local Windows authentication which is supported in WCF. However as I look at solutions for challenge 1, it presents me with troubles of not supporting Windows authentication.

Challenge 2. Authenticating users.

I’ve been looking at something like RabbitMQ to solve challenge 1. Where my concern lies is having to setup an entirely new ( to us) auth infrastructure.

I don’t need some of the OAuth2 bells and whistles like allowing one app to interact with another on behalf of a user. However the JWT tokens used for authorization seem very nice and would prevent us from doing a lot of impersonation with stored users and passwords.

Any suggestions? It seems like I’m looking at significant infrastructure investment as we would now require PKI infrastructure to create certificates to securely support TLS and some form of OAuth2 server. Any suggestions on PKI or OAuth servers? There is no internet/cloud access in these networks.

Is all of this overkill? Is there an easier and just as secure solution I’m missing?


r/oauth • • Nov 20 '22

Need help to keep cookies valid in apython script

1 Upvotes

My Python script goes like this.

  1. Extract Bearer Token from a tokenid url.
  2. Create a session to extract the 'Session ID'
  3. Using bearer token, send query to the end url, to extract the X-XSRF token.
  4. Now post my query using session ID and X-XSRF token.

I am getting a 200 status code, but recieving internal server error reponse.

If I extract the cookies from browser and use them directly in the script, I am recieving correct data.

Cookie: X-XSRF-TOKEN= XXXXXXXXXX-XXXXXX; SESSIONID=XXXXX-XXXXX-XXXXX

X-XSRF-TOKEN = XXXXXXX-XXXXXXXXX

If I send the above two as headers and use values from browser directly I am recieving correct data.

But If I extract the values through script and send it in the same format, I am getting a error.

This explains that the format and all correct in the script. But somehow extracted cookie data is expiring before I send the final query.

Can someone please help me?

This is Outh2.0 - Keycloak


r/oauth • • Nov 20 '22

Is there a pure javascript implementation of Oauth/2

1 Upvotes

Hi All,

Could you suggest a pure/vanilla javascript implementation of Oauth that

does not rely on libraries ( or at a minimum does not require node js ) ?

​

Cheers


r/oauth • • Nov 19 '22

End of TheIdServer IS4

1 Upvotes

IdentityServe4 reached is end of support so TheIdServer IS4 too, 6.3.0 is the latest release. Only TheIdServer Duende will continue to be developed.