Book Image

Mastering OAuth 2.0

Book Image

Mastering OAuth 2.0

Overview of this book

OAuth 2.0 is a powerful authentication and authorization framework that has been adopted as a standard in the technical community. Proper use of this protocol will enable your application to interact with the world's most popular service providers, allowing you to leverage their world-class technologies in your own application. Want to log your user in to your application with their Facebook account? Want to display an interactive Google Map in your application? How about posting an update to your user's LinkedIn feed? This is all achievable through the power of OAuth. With a focus on practicality and security, this book takes a detailed and hands-on approach to explaining the protocol, highlighting important pieces of information along the way. At the beginning, you will learn what OAuth is, how it works at a high level, and the steps involved in creating an application. After obtaining an overview of OAuth, you will move on to the second part of the book where you will learn the need for and importance of registering your application and types of supported workflows. You will discover more about the access token, how you can use it with your application, and how to refresh it after expiration. By the end of the book, you will know how to make your application architecture robust. You will explore the security considerations and effective methods to debug your applications using appropriate tools. You will also have a look at special considerations to integrate with OAuth service providers via native mobile applications. In addition, you will also come across support resources for OAuth and credentials grant.
Table of Contents (22 chapters)
Mastering OAuth 2.0
Credits
About the Author
About the Reviewers
www.PacktPub.com
Preface
11
Tooling and Troubleshooting
Index

About the Reviewers

Shubham Jindal has an avid interest in programming and is currently pursuing his degree in computer science and engineering from Indian Institute of Technology, Delhi. Leaning towards JavaScript, he breathes computers and can be easily spotted hacking around with things, scripting or inspecting elements on the Web. Being a clinophile, he believes in doing smart work. Inclined towards music since childhood, you can inevitably find him with his earphones plugged in.

He is always agog for new opportunities and is striving to establish his very own start-up.

Oleg Mikheev is a computer science enthusiast with over 17 years background both in industry and academia, holding a PhD from one of the top Russian universities. He has completed numerous projects in industries where security is always a top priority—finance, insurance, government.

The list of clients Oleg has worked for includes names such as UBS, CSFB and NYSE, where he has applied a full stack of technologies, specifically IBM WebSphere. Lately, Oleg is focused on start-up ventures, currently working in a financial start-up, Personal Capital.

He has authored a number of articles for the Java World journal, contributed to open source projects and reviewed a book on Struts 2.