OAuth2.0ã¾ã¨ã speakerdeck ã¯ãã¡ãâ https://speakerdeck.com/satot/jin-geng-wen-kenaioauth2-dot-0#Read less
OAuth2.0ã¾ã¨ã speakerdeck ã¯ãã¡ãâ https://speakerdeck.com/satot/jin-geng-wen-kenaioauth2-dot-0#Read less
OAuth 2.0 + OpenID Connect ã®ãã«ã¹ã¯ã©ããå®è£ è ãç¥è¦ãèªã â Qiita ã£ã¦ã®ã«ãªãããã©ãã¼ã¢ãããããçãªã®ãæ¥ãã®ã§ã ãã£ã¨èªãã ææ³ã¨ãã¦ã¯ããOpenID Connect ã® OPTIONAL ãªæ©è½å ¨é¨å®è£ ãããããã大å¤ã§ãããã¨ããæããï¼Authlete ã«é¢ãã¦ã¯ãOpenAM ã¿ãããªæãã§ä½¿ããããOpenAM ããã¯ããã«ç°¡åã«ä½¿ãã代ããã«ææã®ä½ããªãã ãããªãã¨ããã¤ã¡ã¼ã¸ã§ãï¼ OAuth ã¯å¿ è¦ãªã®ãï¼ Basic èªè¨¼ã¯æ»ãã ã ã¦ã¼ã¶ã¼åä½ã§ã® API ã®ã¢ã¯ã»ã¹ã³ã³ããã¼ã«ããããã§ãã ã£ã¦ããåæã§è©±ããã¨ãOAuth 以å¤ã¾ã¨ããªé¸æè¢ãç¡ãããããªãã§ããããã OAuth ã®å種 Extension (RFC 6749 & 6750 以å¤ã«ãããããã) ã«é¢ãã¦ã¯ãé©å®å¿ è¦ãªã®ãå®è£ ããã°ãããã ãã©
oauth2_proxyã便å©ã§ã°ã°ãã¨å°å ¥æé ãçµæ§åºã¦ããã®ã ãã©ãä»åç´¹ä»ããã®ã¯ï¼ç°å¢ã«ãã£ã¦ã¯ï¼ããã«ä¾¿å©ã«ä½¿ãããã¦ãæ¹æ³ã§ãã ãªã«ãããã®ãã¨ããã¨REAMDEã«æ¸ãã¦ããã¾ãã Configuring for use with the Nginx auth_request directive The Nginx auth_request directive allows Nginx to authenticate requests via the oauth2_proxy's /auth endpoint, which only returns a 202 Accepted response or a 401 Unauthorized response without proxying the request through. For example: ãµã³ãã«è¨å®ããã
key = $key; $this->secret = $secret; $this->callback_url = $callback_url; } function __toString() { return "OAuthConsumer[key=$this->key,secret=$this->secret]"; } } class OAuthToken { // access tokens and request tokens public $key; public $secret; /** * key = the token * secret = the token secret */ function __construct($key, $secret) { $this->key = $key; $this->secret = $secret; } /** * generate
ISUCON4 ã§æºåªåãã @catatsuy ã§ãã è³éã®ä½¿ãéã¯ã¾ã èãã¦ãã¾ããã ã¨ããã§ãã¯ã·ãæ ªå¼ä¼ç¤¾ã§ã¯å¬ã¤ã³ã¿ã¼ã³ãããã¾ãï¼ ã¨ã³ã¸ãã¢åããpixivéçºã®bugãªã¹ãããã®è±åºï¼ã¨ã³ã¸ãã¢è·ã¤ã³ã¿ã¼ã³ - ãã¯ã·ãæ ªå¼ä¼ç¤¾ æ¡ç¨ãµã¤ã ISUCON4 ã®äºé¸åé¡ã解ãã ãã§ã¤ã³ã¿ã¼ã³ã«åå ã§ãããã£ã³ã¹ãªã®ã§ãã²ææ¦ãã¦ã¿ã¦ãã ããï¼ï¼1 pixiv/intern2014w ãã®è¨äºã¯å½åã¯ã¢ããã³ãã«ã¬ã³ãã¼ã®è¨äºã«ããäºå®ã§ãããï¼ä»ãæ¬ã ã¨å§åããããããã®ã§ä»å ¬éãã¾ãã ãªããã®è¨äºã¯ ãã¯ã·ãæ ªå¼ä¼ç¤¾ Advent Calendar 2014 - Qiita ã® -17 æ¥ç®ã®è¨äºã§ãã ä»ã¾ã§ã®ç¤¾å ãã¼ã«ã®èªè¨¼ã¯åãµã¼ãã¼ã«è¨å®ããã¦ããããã«éè·è ãªã©ã®å¯¾å¿ãé常ã«å¤§å¤ã§ãããããã§æè¿ã®ãã¯ã·ãæ ªå¼ä¼ç¤¾ã§ã¯ typester/gate ãå°å ¥ãã
Basicèªè¨¼ã¨OAuthã¨ãã®è¾ºã®æ å ±ã«ã¤ãã¦æ´çãã¦ãããOAuthãèªè¨¼ã»èªå¯ã«ã¤ãã¦èª¬æãããã¨ããã¨ã1æåè¨è¿°ãããã³ã«èª¤ããå«ã¾ãã¦ãã¾ãå¯è½æ§ãããã®ã§ãæ¬å½ã«ç·å¼µæãæã£ã¦è¨è¿°ããªããã°ãªããªããããã§ããªãããã®æç« ã«ã¯ããããã®èª¤ããå«ã¾ãã¦ããã Usernameã¨Passwordãåãåã£ã¦èªè¨¼ããå½¢å¼ã®èªè¨¼æ¹æ³ãUsernameã«ã¯Emailã使ããã¨ããã (è¦ã¯å ¨ã¦ã¼ã¶ã®ä¸ã§ä¸æãªãã¨ãä¿è¨¼ããã¦ãã¦ãã¤ä»ã®äººããã®å¤ãç¥ã£ã¦ãã¦ãç¹ã«åé¡ããªãã¨ããæ å ±ã§ããã°OK)ãPasswordã¯æ¬äººããç¥ãå¾ãªãæ å ±ã OAuthã¨ããä»æ§ã«åã£ã¦æä¾ãããèªå¯æ¹æ³ãå¤ãOAuth 1.0ã¨ãOAuth 1.0ã®è¤éãªã¨ãããªã©ãæ¹åããOAuth 2.0ããããä¸è¬çã«ã¯OAuth 2.0ã使ããã¨ãå¤ãããä¾ãã°å¹¾ã¤ãã®ãµã¼ãã¹ã®æä¾ãã¦ããèªå¯æ¹æ³ã¯OAut
Jenkins ã« Bitbucket ã®ã¢ã«ã¦ã³ãã§ãã°ã¤ã³ããããªã¼ã¨æã£ãã®ã§æ¸ãã¦ã¿ãã GitHub - mallowlabs/bitbucket-oauth-plugin: A Jenkins Plugin that supports authentication via Bitbucket OAuth è¨å®ç»é¢ã¯ãããªæãã Bitbucket ã®æ¨©éè¨å®ã¨ã¯å ¨ããªã³ã¯ããªãã®ã§ã誰ã対å¿ã㦠Pull Request ä¸ããã ã¢ãããã¼ããµã¤ãã«ç»é²ããæ°ãããã¾ãç¡ãã®ã§ãä¸ãä¸å¿ è¦ãªäººããããã¢ãã¼ã«ãã¦ãã ããã (2013/05/30 追è¨) ã¾ããã®ã¢ãã¼ã«ãåããã®ã§ã¢ãããã¼ããµã¤ãã«å ¬éãã¾ããã ãã©ã°ã¤ã³ã®æ©è½ã«ã¤ãã¦ã¯æ³åéãã ã¨æãã®ã§ã 以ä¸ã« Bitbucket ã® OAuth ã使ãæã«æ³¨æãã¹ãç¹ãªã©ãã¡ã¢ãã¦ããã åç §ãã¹ãããã¥ã¡ã³ã
ãã¡ãããã¼ã© Notion/Jira/Confluence/GitHub/OneLogin/AWS/GCPãªã©éçºç®¡çãã¼ã«ã試ãã¦éç¨ãã¦ããããã° ã¯ããã¦ä½¿ã£ããã©è¶ 便å©ã ã ⪠omniauth ã£ã¦ Rails 㧠OAuth 対å¿ãã¦ãã ID ã¨ãã®èªè¨¼æ©è½ãä½ã£ã¦ããã gem ãªã®ãã ã¦ã£ããçµ±ä¸è¦æ ¼ã ã¨æã£ã¦ãã gitlab ã«çµã¿è¾¼ãã®ã¯è¶ ç°¡åã å¿ è¦ãª gem ã¯æ§ç¯ããã¨ãã«å ¥ãã¦ããã®ã§ãè¨å®ãã¡ã¤ã«ã«è¿½è¨ããã ãã ãããã¡ãã google APIs ã® ID ã¨ãã¯å¿ è¦ã ãã©ã Google APIs ã®ã¢ã«ã¦ã³ããä½æ [API Console](https://developers.google.com/:title=Google Developers]ã®ä¸é¨ã«ãªã³ã¯ããã[http://code.google.com/apis/console)
OAuthãããã¤ããæä¾ãããã¨ã«ãªã£ãã¨ãã¦ãã¢ã¯ã»ã¹ãã¼ã¯ã³ã«æå¹æéãè¨ããã¹ããã©ããã«ã¤ãã¦èããããOAuth 2.0ã®ä»æ§ã«ã¯ã¢ã¯ã»ã¹ãã¼ã¯ã³ã®æéåãã«é¢ä¿ããä»æ§ãå®ç¾©ããã¦ããããã»ãã¥ãªãã£ãããå¼·åºã«ããããã«ã¢ã¯ã»ã¹ãã¼ã¯ã³ã¯ä¸å®æéã§æéåãã«ããã¹ãã ã¨ãã主張ããã£ãã¨æã (確èªãã¦ããªãã®ã§ç¡ããããããªã)ãããããªãããä¾ãã°GitHub API v3ã§ã¯ã¢ã¯ã»ã¹ãã¼ã¯ã³ã«æå¹æéãè¨ãã¦ããªãããã®æ稿ã§ã¯ãã¢ã¯ã»ã¹ãã¼ã¯ã³ã®æå¹æéã«é¢ä¿ãã¦èµ·ããå¾ãåé¡ãåãä¸ããã ã¢ã¯ã»ã¹ãã¼ã¯ã³ã«æå¹æéãæããã¦ããã¨ã¡ãã£ã¨å®å ¨ ã¢ã¯ã»ã¹ãã¼ã¯ã³ãæªæã®ãã第ä¸è ã«æ¼æ´©ãã¦ãã¾ã£ãå ´åããã®ã¢ã¯ã»ã¹ãã¼ã¯ã³ã«èªå¯ããã¦ããããããæä½ãå®è¡å¯è½ã«ãªã£ã¦ãã¾ãã¨ããåé¡ãã¾ãåå¨ãããããã§ããã¢ã¯ã»ã¹ãã¼ã¯ã³ã«æå¹æéãåå¨ãã¦ããã¨ããã°ããã®æ
Googleèªè¨¼ãªãªãã¼ã¹ããã¯ã·ï¼éçã³ã³ãã³ãé ä¿¡ãµã¼ãã¼ãgateã - unknownplace.orgã§ç´¹ä»ããã¦ãããtypesterããã®gateã¨ãããGoogleã®OAuth2èªè¨¼ä»ããããã·ãµã¼ããã¨ã¦ã便å©ããã ã£ãã®ã§ãå³åº§ã«ä½¿ããããªã£ãã ããã¯ãæ¨ä»å¢ãã¤ã¤ããã¡ããªã¯ã¹ç³»ã®ãã¼ã«ã ã¨ãã®ãã¤ã³ã¿ã¼ãããä¸ã«ç½®ãã¤ã¤ãã社å ã®ã¿ã«æä¾ããããµã¼ãã¹ãç«ã¦ãã«éãã¦ãããã³ãã«nginxããããå ´åã«ãèªè¨¼ã®ãã¨ãèããã®ãã ãããã¨ããããnginxã®è¨å®èªä½ãã ããã¿ãããªã¨ãã«å½¹ç«ã¤ãã¼ã«ã§ãããã®éãèªåã¨ãçã«ã¯GitHubã®organizationã§ã¢ã«ã¦ã³ã管çã§ããã¨ããã«ããã®ã§ãGitHub対å¿ããã¦pull requestãéã£ãã¨ããmergeããã¾ããããããã¨ããããã¾ãã ä¼ç¤¾ã§éç¨ãã¦ããorganizationãfoo_orga
Gmail ã®ã¡ã¼ã«ã OAuth çµç±ã§èªããã¨ãã§ãããã¨ãä»æ´ãªããç¥ã£ãããªãããã£ã¨ãGmail ã¯ã¦ã¼ã¶åã»ãã¹ã¯ã¼ãèªè¨¼ããã§ããªãã¦ä¸ä¾¿ã ãªã ãã¹ã¯ã¼ãæ¸ããããªããªã OAuth ã§ããããªãã㨠OAuth ãã§ããªããã®ã ã¨æãããã§ããã ã§ãç°¡åã«èªããã¢ã¸ã¥ã¼ã«ãããããªãã¨æã£ããã©ãã¡ãã£ã¨è¦ãæãã§ã¯ãªãã®ã§èªåã§æ¸ãã¦ã¿ãã https://gist.github.com/cho45/5814655 Gmail + OAuth ã®åºç¤ç¥è æ¦è¦ã¨ãã¦ã¯ OAuth ã®ã¢ã¯ã»ã¹ãã¼ã¯ã³ãå¾ã ã¡ã¼ã«ã¢ãã¬ã¹ (ã¢ã«ã¦ã³ãå) + ã¢ã¯ã»ã¹ãã¼ã¯ã³ã使ã£ã¦ SASL XOAUTH2 ãã©ã¼ãããã®æååãä½ã IMAP ã使ããAUTHENTICATE ã³ãã³ãã§ä¸è¨æååãéã£ã¦èªè¨¼ãã ã¨ããæãã§ãOAuth ã¯ä½¿ãããã©ãWebAPI 㧠Gmai
ã¡ã³ããã³ã¹
ãç¥ãã
é害
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}