42
池澤あやかと学ぼう! はじめての OAuth OpenID Connect

池澤あやかと学ぼう!: はじめてのOAuthとOpenID Connect - JICS 2014

Embed Size (px)

Citation preview

  • 1. OAuthOpenID Connect

2. https://www.facebook.com/ayaka.rb 3. http://next.rikunabi.com/tech/docs/ct_s03600.jsp?p=002298 4. http://fb.dev-plus.jp/column1/column1_1/ 5. 2010831Twitter API Basic OAuth 1.0 6. 7. 8. http://internet.watch.impress.co.jp/docs/news/20120209_510649.html 9. http://www.soumu.go.jp/menu_news/s-news/01ryutsu03_02000063.html 10. http://www.soumu.go.jp/main_content/000265404.pdf 11. ID http://klout.com 12. https://developers.facebook.com/products/login/ 13. https://github.com/nov/jics_fb 14. StandardProprietary 15. OpenID Connect OAuth 2.0 + Identity Layer 16. OpenID ConnectRP Demo 17. ID Token UserInfo 18. [3]! OAuth access token ID Toke 19. ID Token (JSON Web Token)iss Issuersub Subject, End-user Identieraud Audience, Client IDiat - issued atexp - expiry 20. http://openid.net/connect/ 21. Implicit = 22. https://developers.facebook.com/products/login/ 23. access token 24. GET /meUser Info : 25. Weak Point GET /meUser Info : 26. Weak Point Token Replace GET /meUser Info : 27. Weak Point Token Replace GET /meDierent User DataUser Info : 28. Implicit in Secure 29. ID Token 30. ID Token 31. response_type=token id_token ID Token 32. ID Token (JSON Web Token)iss Issuersub Subject, End-user Identieraud Audience, Client IDiat - issued atexp - expiry 33. (issuer = IdP) (subject = end-user) (audience = client) 34. OpenIDOIDF-J OpenID API 35. OIDF-J ID OpenID 2010 [email protected] Copyright 2013 OpenID Foundation Japan. All Rights Reserved.6