No video

What is OAuth with PKCE and How Does it Work? | Way of the Future

  Рет қаралды 4,405

AppSecEngineer

AppSecEngineer

Күн бұрын

Пікірлер: 8
@senk0than
@senk0than 3 жыл бұрын
what an amazing content...Thanks much Abhay
@AppSecEngineer
@AppSecEngineer 3 жыл бұрын
Glad you liked it!
@SudhanshuSrivastavaIndia
@SudhanshuSrivastavaIndia Жыл бұрын
Is it good practice to get PKCE as part of configuration injection from an app to a Login Framework which has OAuth 2.0?
@guesswho2306
@guesswho2306 2 жыл бұрын
Good explanation! Liked it! I have QQ - at 5:08 where we are sending encrypted string with type of hashing s256 so anyone easily can decrypt that request
@AppSecEngineer
@AppSecEngineer 2 жыл бұрын
Thanks for your question. Just to clarify. This is not an encrypted string. Its a secure random value that is subsequently subjected to a SHA256 hash. So there's no question of decryption. And attempting to crack/collide this hash is nearly impossible because of the nature of the underlying random value. In addition to all these constraints, remember that this value is a one-time use value only. Its never used subssequently, and is transmitted over HTTPS, so these risks are quite mitigated. I hope we've clarified.
@guesswho2306
@guesswho2306 2 жыл бұрын
Got it. Thanks again!
@sanofamotivation
@sanofamotivation 6 ай бұрын
Could you please create vedio on other grant types aswell
@AppSecEngineer
@AppSecEngineer 6 ай бұрын
Hey, we'll surely do that.
An Illustrated Guide to OAuth and OpenID Connect
16:36
OktaDev
Рет қаралды 581 М.
Everything You Ever Wanted to Know About OAuth and OIDC
33:21
Magic? 😨
00:14
Andrey Grechka
Рет қаралды 20 МЛН
Oh No! My Doll Fell In The Dirt🤧💩
00:17
ToolTastic
Рет қаралды 9 МЛН
When you discover a family secret
00:59
im_siowei
Рет қаралды 20 МЛН
OAuth 2.0 & OpenID Connect (OIDC): Technical Overview
16:19
VMware End-User Computing
Рет қаралды 157 М.
OAuth 2 scope design for security
23:38
Manning Publications
Рет қаралды 3,1 М.
OAuth Authorization code flow
11:49
Jan Goebel
Рет қаралды 51 М.
oAuth for Beginners - How oauth authentication🔒 works ?
10:43
OAuth 2.0 explained with examples
10:03
ByteMonk
Рет қаралды 125 М.
OAuth 2.0 and OpenID Connect (in plain English)
1:02:17
OktaDev
Рет қаралды 1,7 МЛН
OAuth 2.0: Implicit, Authorization Code, and PKCE
9:12
Ping Identity TV
Рет қаралды 14 М.
OpenID Connect - Basics
13:29
Sascha Preibisch
Рет қаралды 26 М.
What's going on with the OAuth 2.0 Implicit flow?
17:18
OktaDev
Рет қаралды 83 М.
Magic? 😨
00:14
Andrey Grechka
Рет қаралды 20 МЛН