Zum Hauptinhalt springen
••••
Sichere ProgrammierungYour RV park website is leaking bookings. Here is where.(05.10.2026 um 02:43 Uhr)
••
Sichere ProgrammierungRetry logic can trip the card network's own decline-rate monitor(05.10.2026 um 02:45 Uhr)
•
Sichere ProgrammierungCross-Chain Bridge Risk Assessment: Poloniex(05.10.2026 um 02:47 Uhr)
••
Sichere ProgrammierungREST API Authentication: Cookie+Nonce vs. Application Passwords(05.10.2026 um 02:48 Uhr)
•••••
Sichere ProgrammierungYour RV park website is leaking bookings. Here is where.(05.10.2026 um 02:43 Uhr)
••
Sichere ProgrammierungRetry logic can trip the card network's own decline-rate monitor(05.10.2026 um 02:45 Uhr)
•
Sichere ProgrammierungCross-Chain Bridge Risk Assessment: Poloniex(05.10.2026 um 02:47 Uhr)
••
Sichere ProgrammierungREST API Authentication: Cookie+Nonce vs. Application Passwords(05.10.2026 um 02:48 Uhr)
•
Intelligence View
⚡ tsecurity.de Intelligence

OAuth andOpenID - Introduction

Hello, welcome to my second post at Dev.to! :D We'll cover the basics of OAuth and OpenId and try to make the concept simple enough to memoize for interviews,…

Beitrag
0
Seite
0
↗ Quelle (dev.to)
Social ReaktionenReagiere als Erste:r — dein Feedback zählt!




Hello, welcome to my second post at Dev.to! :D



We'll cover the basics of OAuth and OpenId and try to make the concept simple enough to memoize for interviews, let's go!






First thing, OpenID and OAuth are different things.






Authorization



OAuth is responsible for issuing a "token" after you provide your credentials to the OAuth server, which answers back with the access token that gives you access to APIs but doesn't carry any user data. That's what they call authorization.






Authentication



OpenId implements the concept of user identity on top of the OAuth token mechanism, the difference is that you also receive an ID Token alongside the access token. That's what they call authentication.




const OAuth = 'Authorization';
const OpenID = 'Authentication';






Simple, isn't it? Well, that's what they say. Look at the diagram below:



OAuth and OpenID Diagram



Link to the full diagram:

https://infosec.mozilla.org/guidelines/assets/images/OIDC_sequence_diagram.png



That's basically the flow for an OpenID authentication.



The main difference between this type of authentication and the standard cookie model is that it has its own authentication server and this server has full access agency, meaning controlling access by registering applications upfront and generating ClientID's and ClientSecret's for each registered client on this server.



These Secret's and ID's are now used on the clients to perform requests to the authentication server, which provides the token.



I think that's a good introduction to OAuth and OpenID.



What've learned so far:



1 - Authentication and Authorization

2 - Authorization Server

3 - ClientID and ClientSecret



In the next articles, I'll cover more about the token and its different strands.

🔍 CTI & Forensik

Cyber Threat Intelligence & Forensik

ATT&CK-Navigator · IoC-Radar · Exploit-Belege
IoC Intelligence
1 Indikatoren · Defanged · STIX 2.1
dev[.]to
CTI Threat Relationship Graph
Akteure · Techniken · Beziehungen
2 Knoten · 1 Relationen
CVE / Incident Threat Actor Software MITRE ATT&CK CWE Weakness IoC
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten OAuth andOpenID - Introduction

Thematisch verwandte Begriffe: OAuth, andOpenID, Introduction · 6 Treffer

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

💬 Kommentare werden geladen…
Zum Aktualisieren ziehen
Nächster Beitrag