News

Oleg Dulin Oleg Dulin OAuth 2.0 authorization flow. The third-party app is unaware of the user’s credentials. You, as the resource owner, own your data stored on the resource server.
Hammer isn't just questioning OAuth 2.0, he's abandoned it entirely and completely erased himself from the project, calling it "a bad protocol... bad enough that I no longer want to be associated ...
In a simplified manner, using Facebook.com as identity provider, for example, the OAuth flow works like this: When the user asks a website to log them in using their Facebook account, the website ...