SECCON Beginners Live 2023ãJWTã»ãã¥ãªãã£å ¥éãã®çºè¡¨è³æã§ãã

SECCON Beginners Live 2023ãJWTã»ãã¥ãªãã£å ¥éãã®çºè¡¨è³æã§ãã
2020å¹´3æ17æ¥ãæ ªå¼ä¼ç¤¾Authleteã主å¬ãããOAuth & OIDC åå¼·ä¼ ãªã¿ã¼ã³ãºãå ¥éç·¨ãããéå¬ãå社ã®å ±ååµæ¥è ã§ãããããã°ã©ãã¼å ¼ä»£è¡¨åç· å½¹ã§ãããå·å´è²´å½¦æ°ããOAuth 2.0 / OIDCã®ä»æ§ã«ã¤ãã¦è§£èª¬ãã¾ããã åé ã¯ãOAuth 2.0ã®æ¦å¿µãèªå¯ã»èªè¨¼ã¾ã§ã®æµãã¨ããããç解ããä¸ã§é¿ãã¦ã¯éããªã3ã¤ã®æè¡ä»æ§ï¼JWSã»JWEã»JWTï¼ã«ã¤ãã¦ã®è§£èª¬ã§ãã OAuth 2.0ã¨ã¯ å·å´è²´å½¦æ°ï¼æ ªå¼ä¼ç¤¾Authleteã®å·å´ã§ããæ¬æ¥ã¯ãOAuthã¨OpenID Connectã®å ¥éç·¨ãã¨ãããã¨ã§ãªã³ã©ã¤ã³åå¼·ä¼ãéå¬ãã¾ãã®ã§ããããããé¡ããã¾ããæåã«OAuth 2.0ã®æ¦è¦ã®èª¬æããã§ãã ããã°ã«æ¸ãã¦ããå 容ã¨ä¸ç·ãªãã§ãããã¾ãã¦ã¼ã¶ã¼ã®ãã¼ã¿ãããã¾ãããã®ã¦ã¼ã¶ã¼ã®ãã¼ã¿ã管çããã®ãããªã½ã¼ã¹ãµã¼ãã¼ã§ãããã®ã¦ã¼ã¶ã¼ã®ã
ãã¯ãããããã¾ããritouã§ãã (â ï¸èªå¯ã¤ãã³ãã®èå¥åã®ããããã¡ãã£ã¨è¦ç´ãã¾ããï¼æåã«è¦ã¦ããã ããæ¹ã¯ããä¸åã©ããï¼) ååããã¤ããªããåã¨å¼ã°ãã OAuth 2.0 ã®ãã¼ã¯ã³å®è£ ã«ã¤ãã¦æ¸ãã¾ããã ritou.hatenablog.com ãã®ç¶ãã¨ã㦠JWT(JWS) + RDBã§ã§ããå®è£ ä¾ãç´¹ä»ãã¾ãã ç解ããã«ã¯ãããªãã® OAuth 2.0 ã«é¢ããç¥èãå¿ è¦ã«ãªãããããã¾ããããããã£ããåèã«ãã¦ã¿ã¦ãã ããã ä½ãèããã®ã OAuth 2.0ã®Refresh Token, Access Tokenãèãã¾ãã è¦ä»¶ããæ´çãã¾ãããã è¦ä»¶ çµæ§ããã¾ãããæä½éã® OAuth 2.0 ã® Authorization Server ãå®è£ ãããã¨æã£ãããããããã¯ãããªãã¨ãããªãã§ãããã RFC6750 ã§å®ç¾©ããã¦ãã Bear
éã«ãRFC 6749 以å¤ã§å®ç¾©ããã¦ããèªå¯ããã¼ããµãã¼ãããå ´åãæ°ãã«å¥ã®ã¨ã³ããã¤ã³ãã®å®è£ ãå¿ è¦ã«ãªããã¨ãããã¾ããä¾ãã° CIBAï¼Client Initiated Backchannel Authenticationï¼ã§ã¯**ããã¯ãã£ãã«èªè¨¼ã¨ã³ããã¤ã³ãï¼backchannel authentication endpointï¼ãããã¤ã¹ããã¼ï¼RFC 8628ï¼ã§ã¯ããã¤ã¹èªå¯ã¨ã³ããã¤ã³ã**ï¼device authorization endpointï¼ã®å®è£ ãæ±ãããã¾ãã ãã®è¨äºã§ã¯ãèªå¯ã¨ã³ããã¤ã³ãã¨ãã¼ã¯ã³ã¨ã³ããã¤ã³ããå®è£ ãã¾ãããµãã¼ãããèªå¯ããã¼ã¯èªå¯ã³ã¼ãããã¼ã®ã¿ããµãã¼ãããã¯ã©ã¤ã¢ã³ãã»ã¿ã¤ãã¯ãããªãã¯ã®ã¿ã¨ãã¾ãã 2. 注æç¹ ä¸è¨ã®çç±ãããã³æ¸ããã¦ããªããã®ä»ã®çç±ã«ãããæ¬å®è£ ã¯åç¨å©ç¨ã«ã¯é©ãã¦ãã¾ããã ã»ãã¥ãªãã£
èªè¨¼ã¯åç´ãªæ¦å¿µã§ãå¥ã®è¨èã§è¨ãã°æ¬äººç¢ºèªã§ããWeb ãµã¤ãã«ãããæ¬äººç¢ºèªã®æãä¸è¬çãªæ¹æ³ã¯ ID ã¨ãã¹ã¯ã¼ãã®çµãæ示ãã¦ããããã¨ã§ãããæç´ãè¹å½©ãªã©ã®çä½æ å ±ãç¨ããæ¬äººç¢ºèªæ¹æ³ããããã¾ããã©ã®ãããªç¢ºèªæ¹æ³ã ã¨ãã¦ã (ã¯ã³ã¿ã¤ã ãã¹ã¯ã¼ãã使ã£ããã2-way èªè¨¼ã ã£ãããã¦ã)ãèªè¨¼ã¨ã¯ã誰ãªã®ããç¹å®ããããã®å¦çã§ããéçºè ã®è¨èã§ããã表ç¾ããã¨ããèªè¨¼ã¨ã¯ãã¦ã¼ã¶ã¼ã®ä¸æèå¥åãç¹å®ããå¦çãã¨è¨ãã¾ãã ä¸æ¹ãèªå¯ã®ã»ãã¯ãã誰ãããã誰ã«ãããä½ã®æ¨©éãããã¨ããä¸ã¤ã®è¦ç´ ãåºã¦ãããããè¤éã«ãªãã¾ããå ãã¦ã話ãããããããã¦ããã®ã¯ããã®ä¸ã¤ã®è¦ç´ ã®ãã¡ãã誰ããã決ããå¦çããèªè¨¼å¦çãã§ããã¨ããç¹ã§ããããªãã¡ãèªå¯å¦çã«ã¯ãã®ä¸é¨ã¨ãã¦èªè¨¼å¦çãå«ã¾ãã¦ããããã話ãããããããªã£ã¦ããã®ã§ãã èªå¯ã®ä¸è¦ç´ ãããå°ãç¾å ´ã«è¿ãè¨èã§è¡¨
ã¯ã¦ãªã°ã«ã¼ãã®çµäºæ¥ã2020å¹´1æ31æ¥(é)ã«æ±ºå®ãã¾ãã 以ä¸ã®ã¨ã³ããªã®éããä»å¹´æ«ãç®å¦ã«ã¯ã¦ãªã°ã«ã¼ããçµäºäºå®ã§ããæ¨ããç¥ãããã¦ããã¾ããã 2019å¹´æ«ãç®å¦ã«ãã¯ã¦ãªã°ã«ã¼ãã®æä¾ãçµäºããäºå®ã§ã - ã¯ã¦ãªã°ã«ã¼ãæ¥è¨ ãã®ãã³ãæ£å¼ã«çµäºæ¥ã決å®ãããã¾ããã®ã§ã以ä¸ã®éãã確èªãã ããã çµäºæ¥: 2020å¹´1æ31æ¥(é) ã¨ã¯ã¹ãã¼ãå¸æç³è«æé:2020å¹´1æ31æ¥(é) çµäºæ¥ä»¥éã¯ãã¯ã¦ãªã°ã«ã¼ãã®é²è¦§ããã³æ稿ã¯è¡ãã¾ãããæ¥è¨ã®ã¨ã¯ã¹ãã¼ããå¿ è¦ãªæ¹ã¯ä»¥ä¸ã®è¨äºã«ãããã£ã¦æç¶ãããã¦ãã ããã ã¯ã¦ãªã°ã«ã¼ãã«æ稿ãããæ¥è¨ãã¼ã¿ã®ã¨ã¯ã¹ãã¼ãã«ã¤ã㦠- ã¯ã¦ãªã°ã«ã¼ãæ¥è¨ ãå©ç¨ã®ã¿ãªãã¾ã«ã¯ãè¿·æãããããããã¾ãããã©ãããããããé¡ããããã¾ãã 2020-06-25 è¿½è¨ ã¯ã¦ãªã°ã«ã¼ãæ¥è¨ã®ã¨ã¯ã¹ãã¼ããã¼ã¿ã¯2020å¹´2æ28
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}