Share E-Book
Scan to open this page

Scan with your phone to open this page

Author: Justin Richer, Antonio Sanso

Rating No ratings yet

Summary OAuth 2 in Action teaches you the practical use and deployment of this HTTP-based protocol from the perspectives of a client, authorization server, and resource server. You'll learn how to confidently and securely build and deploy OAuth on both the client and server sides. Foreword by Ian Glazer. Purchase of the print book includes a free eBook in PDF, Kindle, and ePub formats from Manning Publications. About the Technology Think of OAuth 2 as the web version of a valet key. It is an HTTP-based security protocol that allows users of a service to enable applications to use that service on their behalf without handing over full control. And OAuth is used everywhere, from Facebook and Google, to startups and cloud services. About the Book OAuth 2 in Action teaches you practical use and deployment of OAuth 2 from the perspectives of a client, an authorization server, and a resource server. You'll begin with an overview of OAuth and its components and interactions. Next, you'll get hands-on and build an OAuth client, an authorization server, and a protected resource. Then you'll dig into tokens, dynamic client registration, and more advanced topics. By the end, you'll be able to confidently and securely build and deploy OAuth on both the client and server sides. What's Inside Covers OAuth 2 protocol and design Authorization with OAuth 2 OpenID Connect and User-Managed Access Implementation risks JOSE, introspection, revocation, and registration Protecting and accessing REST APIs About the Reader Readers need basic programming skills and knowledge of HTTP and JSON. About the Author Justin Richer is a systems architect and software engineer. Antonio Sanso is a security software engineer and a security researcher. Both authors contribute to open standards and open source. Table of Contents Part 1 - First steps What is OAuth 2.0 and why should you care? The OAuth dance Part 2 - Building an OAuth 2 environment Building a simple OAuth client Building a sim

AI Reading Assistant

Whole-book reading guide from stratified index samples; jump to passages in the text

AI guide
【One-Line Pitch】 A hands-on guide to understanding and deploying OAuth 2.0 securely, written for developers and identity professionals who need to move from "I've heard of OAuth" to building real client, authorization server, and resource server implementations. If you work with APIs and need to protect them without reinventing access control, this book gives you both the protocol mechanics and the practical judgment to avoid common anti-patterns. 【Book Arc】 - **Opening (~0%–10%)**: Introduces OAuth 2.0 as a delegation framework, explains why it exists, and frames the core problem: how to let a client access a protected resource on behalf of a user without handing over full credentials. Sets up the "valet key" mental model and the four actors. - **Early (~10%–35%)**: Walks through the OAuth "dance" in detail — the authorization code grant, front-channel and back-channel communication, endpoints, tokens, and the roles of resource owner, client, authorization server, and protected resource. Establishes the vocabulary and flow diagrams used throughout. - **Middle (~35%–60%)**: Hands-on construction of a working OAuth ecosystem: building a simple client, a protected resource that accepts bearer tokens, and an authorization server. Covers token passing methods, scope-based access control, and refresh tokens for long-lived access. - **Late (~60%–85%)**: Moves into advanced topics — different grant types and client types, token introspection and revocation, dynamic client registration, and the JOSE stack (JWT, JWS, JWE) for token formats. Also covers OpenID Connect and User-Managed Access as extensions. - **Ending (~85%–100%)**: Focuses on implementation risks, anti-patterns, and best practices for deploying OAuth securely in production, including protecting REST APIs and avoiding common pitfalls that arise from OAuth's flexibility. 【Key Takeaways】 - **OAuth is a delegation framework, not an authentication protocol** (Early): It lets a resource owner grant limited access to a client without sharing credentials. Confusing it with login is a common and dangerous mistake. - **The authorization code grant is the workhorse flow** (Early): The client redirects the user to the authorization server, receives a code, then exchanges it for a token on the back channel. This separation is what makes it secure for web apps. - **Bearer tokens are simple but sensitive** (Middle): They can be passed via Authorization header, form body, or query parameter, but the header is preferred. Anyone who holds the token can use it, so transport security and storage matter. - **Scopes divide functionality** (Middle): Different actions require different scopes, allowing a single token to be valid across multiple resource servers while limiting what each client can do. - **Refresh tokens enable long-lived access without user interaction** (Middle): When an access token expires, the client can use a refresh token to get a new one, which is essential when the user is no longer present. - **OAuth's flexibility is its greatest strength and its biggest risk** (Late): Many pieces are optional, which leads to incompatibility and insecure deployments. Following best practices and avoiding anti-patterns is not optional. - **Advanced extensions like OpenID Connect and JOSE build on OAuth** (Late): OpenID Connect adds identity, while JOSE provides signing and encryption for tokens. These are separate specs but commonly used together. - **Implementation risks are real and avoidable** (Ending): The book emphasizes that just because you can deploy OAuth in any way doesn't mean you should. Secure deployment requires understanding the threats and following the spec's security considerations. 【Reading Tips】 - **Deep-read the early chapters on the authorization code grant** — this flow underpins most of the book and the exercises. Skim the acknowledgments and foreword. - **Do the exercises** — the book is built around building a client, authorization server, and protected resource. The hands-on code is where the concepts solidify. - **Pay extra attention to the security chapters near the end** — they distill the anti-patterns and best practices that separate a working demo from a production-safe deployment. - **Use the token and grant type chapters as reference** — when you need to choose a grant type or token format for a real project, revisit the comparisons and trade-offs. - **Don't skip the coverage of scopes and refresh tokens** — these are the practical levers for controlling access and maintaining sessions without user involvement. 【Coverage Limits】 This guide is based on stratified excerpts covering roughly the first half of the book in detail, with lighter coverage of the later chapters on advanced topics and security. Specific implementation details, code listings, and some advanced grant types are not fully represented in the excerpts.
Excerpt 1
1 - First steps What is OAuth 2.0 and why should you care? The OAuth dance Part 2 - Building an OAuth 2 environment Building a simple OAuth client Building a...
View in text
Excerpt 2
protected resources as a rack of servers with a lock icon. ■■ The client is the piece of software that accesses the protected resource on behalf of the resou...
View in text
Excerpt 3
le HTTP request and response. OAuth over non-HTTP channels Although OAuth is defined only in terms of HTTP, several specifications have defined how to move d...
View in text
Excerpt 4
be checked off 4.3.1 Different scopes for different actions In this style of API design, different kinds of actions require different scopes in order for the...
View in text
Excerpt 5
kfully, when we saved the code in the last section, we also 90 Chapter 5 Building a simple OAuth authorization server As it turns out, HTTP forms and query s...
View in text
Excerpt 6
own behalf? This includes accessing APIs that don’t neces- sarily map to a single user, such as bulk data transfers. If so, then you should be using the clie...
View in text
Excerpt 7
ometimes even dangerous. 8 h ttp://intothesymmetry.blogspot.it/2015/06/on-oauth-token-hijacks-for-fun-and.html Registration of the redirect URI 133 If the re...
View in text
Excerpt 8
er via the insecure HTTP protocol. Integrating HSTS in our endpoint is straightforward and, like CORS, requires adding a couple of extra headers. Open up and...
View in text
Tags
AI categories
OAuthAPI SecurityWeb Development
ISBN: 161729327X
Publish Year: 2017
Language: English
Pages: 360
File Format: PDF
File Size: 14.1 MB
Text Preview (First 20 pages)
Registered users can read the full content for free

Register as a Gaohf Library member to read the complete e-book online for free and enjoy a better reading experience.

Generating text preview…