logoalt Hacker News

sandeepkdyesterday at 8:14 AM1 replyview on HN

Its looks simple, sounds simple, however its not. Merging(Being hijacked by) authorization into authentication is probably the slippery slope.


Replies

brabelyesterday at 8:33 AM

OAuth says nothing about authentication other than you have to be redirected back to the client once authentication is complete, by unspecified means, before the client can proceed with authorization and get a token proving they are now authorized to do something. There is no slippery slope.

show 1 reply