Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

all of that, plus the rfcs for oauth2 and oidc are pretty great as well!


Yeah start with https://datatracker.ietf.org/doc/html/draft-ietf-oauth-v2-1-... Deprecating the unsecure&outdated/it's easy to shoot yourself and summarizing so you don't need to go through the rabbit hole of specs...

Also follow the BCP that will remain in a draft state forever(at least for the near future): https://datatracker.ietf.org/doc/html/draft-ietf-oauth-secur...




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: