Webã¢ããªä½ã£ã¦ããã¨ããããªå±é¢ã§ã¦ã¼ã¶ã¼èªè¨¼ãå¿ è¦ã«ãªãå±é¢ããããã¾ããã«ã¤ããã¨æã¦ããªãé¢åã ããé©å½ã«ã¤ããã¨ã»ãã¥ãªãã£ä¸åé¡ã«ãªãã®ã§ãè¦ä»¶ã«å¿ãã¦é©åã«ææãããå¿ è¦ãããã
é©å½ãªãã¤ãããã£ãããããã¤ã¾ã§ãªãã¨ãªãã½ã¼ããã¦ããã¨ãããªãããã ã¨æãã
- èªè¨¼ãªã
- IPã§å¼¾ã
- Basicèªè¨¼ï¼ã½ã¼ã¹ã³ã¼ããè¨å®ãã¡ã¤ã«ã«ãã¹ã¯ã¼ããã¿æ¸ãï¼
- Basicèªè¨¼ï¼DBã«Userãã¼ãã«ãã¤ãã£ã¦ãã¹ã¯ã¼ããä¿åã追å ã¯cliã¨ãã§æåï¼
- login/logoutç»é¢ä½æãcookieãªãmemcacheãªãã«ã»ãã·ã§ã³ãä¿å
- webããã¦ã¼ã¶ã¼ã追å ã§ããããã«
- passwordå¤æ´æ©è½
- OAuth
- OpenID
- mailãéã£ã¦ãªã³ã¯ãã¯ãªãã¯ããã¦ã¡ã¼ã«ã¢ãã¬ã¹ã®ææ確èª
- ã¡ã¼ã«ã¢ãã¬ã¹å¤æ´æ©è½
- ã¡ã¼ã«ã使ã£ã¦ã®ãã¹ã¯ã¼ããªã»ããæ©è½
- OAuthã§ä½ã£ãã¢ããªã¸ã®å¾ããã®ã¡ã¼ã«ã¢ãã¬ã¹ã¨ãã¹ã¯ã¼ã追å ç»é²æ©è½
- äºæ®µéèªè¨¼
ä¸ç¹å®å¤æ°ã®ã¦ã¼ã¶ã¼ãç»é²ããå ´åã«éçºã¨ãã¦æ¥½ãªã®ã¯id/passwordæ¹å¼ã
ã¡ã¼ã«ã¢ãã¬ã¹èªè¨¼ã¨ãããªãç´ç²ãªidã ã¨ããã楽ã§ãã
ããããã¨ãOAuthé¸ã³ãã¡ã ãã©æå¤ã¨ä½¿ãåææªãã
OAuth使ãã¨çºçããåé¡
- ã©ã¤ãã©ãªã®ä¾åã¨ã諸ã ã§ã¯ã¾ãããã
- OAuth provider (Twitterã¨ãFBã¨ãã®ãããã¨ãï¼ã«ä¾åãããã¨ã«ãªã
- è¤æ°ã®OAuth providerã«å¯¾å¿ããã¨1人ã®ã¦ã¼ã¶ã¼ãè¤æ°ã¢ã«ã¦ã³ãéè¤ãã¦ãã¾ãå¯è½æ§ãã§ã¦ãã¦ããã©ããããªã
- Native Appã¤ããã¨ãã«èªè¨¼ã§WebViewéãã¦(myapp(web) -> Twitter -> myapp(web) -> myapp(native))ã¿ãããªcallbackã®åµããããã¡ã«ãªã
- Native Appã®ãã¤ããªå ã«ãµã¼ãã¼å´ã¨åãConsumer Key/Consumer Secretãæã¤ã¨ã»ãã¥ãªãã£ä¸åé¡ãããã®ã§Nativeã§ã¯æããªãããã«ãããªããå¥ã®Consumer Keyãæã¤ãªãããªãã¨ãããªã
- æ´ã«ãã¸ã¡ãªè©±ãããã¨ã¢ããªå WebViewã§å¤é¨ãµã¼ãã¹ã®ãã¹ã¯ã¼ãå ¥åããã¦èªè¨¼ãããã®ã¯fishingã®ããããããã®ã§ã¢ãã¬ã¹ãã¼ãä¿¡é ¼ã§ããå¤é¨ãã©ã¦ã¶ã¢ããªã«é£ã°ãã¦èªè¨¼ãããã»ããè¯ã
追è¨
OAuthã¯èªå¯ã§ãã£ã¦èªè¨¼ã§ã¯ãªãããã¬ãã®è©±ã¯æ¿ç¥ãã¦ããã¾ããç¾å®ã¨ãã¦ãã®è¾ºã«è©³ãããªãã¨ã³ã¸ãã¢ã®çæ§ã¯ãTwitterã§èªè¨¼ãã¨ãã£ããããã¦ã¾ãããTwitterã«OAuthã§èªå¯ãå¾ã¦verify_credential.jsonãå©ããçµæããuser_idãåå¾ããã¨ããã¯èªè¨¼ã¨ãã¦åé¡ãªã使ãã¦ãã¾ãã¨ããç¾å®ãããã¾ãï¼ä½è¨ãªæ¨©éã®èªå¯ãã¤ãã¦ãã¾ããããã£ã¡ããªãã ããã ã§ä½¿ããï¼ãOAuthåç¬ã ã¨èªè¨¼æ©è½ããªãã¨ããã®ã¯äºå®ãªãã§ããä¸è¬çã«è¨ãOAuthã¨ã¯è¦ããã«Twitterã§ããFacebookã§ãããããã®APIã¨çµã¿åããããã¨ã§èªè¨¼æ©è½ãå¾ããã¨ãã§ããããIDãªäººãã¡ã大好ããªOpenIDã®ææ°è¦æ ¼ã§ããOpenID Connectã ã£ã¦OAuthã§access_tokenåå¾ããã¤ãã§ã«Identityãã¤ãã¦ããã¨ããTwitter APIã®verify_credentialãå¼ã¶æéãçãã¦å ±éè¦æ ¼ã«ãã¾ããã¿ãããªããã ããæ¥ææ·±å¤ã«ãããªé·ææ¸ããã¡ã«ãªãã®ã§OAuthãã©ãã¨ãèªè¨¼ã¨ãèªå¯ã¨ãã®è°è«ããããã