ã¢ã¯ã»ã¹ãã¼ã¯ã³ï¼å®ç¾©ãã¢ã¼ããã¯ãã£ã使ç¨æ³ãªã©
ã¢ã¯ã»ã¹ãã¼ã¯ã³ï¼å®ç¾©ãã¢ã¼ããã¯ãã£ã使ç¨æ³ãªã©
ã¢ã¯ã»ã¹ãã¼ã¯ã³ï¼å®ç¾©ãã¢ã¼ããã¯ãã£ã使ç¨æ³ãªã©
ã¢ã¯ã»ã¹ãã¼ã¯ã³ã¯ã大éã®ãã¼ã¿ãå«ãå°ããªã³ã¼ãã§ããã¦ã¼ã¶ã¼ãã¢ã¯ã»ã¹è¨±å¯ãã°ã«ã¼ããæéæ ã«é¢ããæ å ±ã¯ããµã¼ãã¼ããã¦ã¼ã¶ã¼ã®ããã¤ã¹ã«æ¸¡ããã1ã¤ã®ãã¼ã¯ã³å ã«åãè¾¼ã¾ãã¾ãã
ã¢ã¯ã»ã¹ãã¼ã¯ã³ã¯ãå¤ãã®Webãµã¤ãã§ä½¿ç¨ããã¦ãã¾ãããã¨ãã°ãFacebookã®è³æ ¼æ å ±ã使ç¨ãã¦ãSalesforceãªã©å¥ã®Webãµã¤ãã«ã¢ã¯ã»ã¹ãããã¨ããã人ã¯ãã¢ã¯ã»ã¹ãã¼ã¯ã³ã使ç¨ãããã¨ã«ãªãã¾ãã
ã¢ã¯ã»ã¹ãã¼ã¯ã³ã«å«ã¾ãããã®
ä¸è¬çã«ãã¢ã¯ã»ã¹ãã¼ã¯ã³ã«ã¯3ã¤ã®ç°ãªãé¨åãå«ã¾ãã¾ããããããã¹ã¦ãé£åãã¦,ãªã½ã¼ã¹ã«ã¢ã¯ã»ã¹ããã¦ã¼ã¶ã¼ã®æ¨©éãæ¤è¨¼ãã¾ã
ã»ã¨ãã©ã®ã¢ã¯ã»ã¹ãã¼ã¯ã³ã«ã¯ã以ä¸ã®3ã¤ã®éè¦è¦ç´ ãå«ã¾ãã¦ãã¾ãã
- ãããã¼ï¼ãã¼ã¯ã³ã®ã¿ã¤ãã¨ããã¼ã¯ã³ã®ä½æã«ä½¿ç¨ãããã¢ã«ã´ãªãºã ã«é¢ãããã¼ã¿ãå«ã¿ã¾ãã
- ãã¤ãã¼ãï¼ã¢ã¯ã»ã¹è¨±å¯ãæå¹æéãªã©ãã¦ã¼ã¶ã¼ã«é¢ããæ å ±ãå«ã¿ã¾ãã
- ç½²åï¼åä¿¡è ããã¼ã¯ã³ã®ä¿¡é ¼æ§ãä¿è¨¼ããããã®æ¤è¨¼ãã¼ã¿ãå«ã¿ã¾ããé常ããã®ç½²åã¯ããã·ã¥åãããããããããã³ã°ãè¤è£½ã¯å°é£ã§ãã
ãã¤ãã¼ãï¼ã¯ã¬ã¼ã ã»ã¯ã·ã§ã³ã¨ãå¼ã°ãã¾ãï¼ã¯ããã¼ã¯ã³ã®æåã«ä¸å¯æ¬ ã§ãããµã¼ãã¼ä¸ã®ç¹å®ã®ãªã½ã¼ã¹ã«ã¢ã¯ã»ã¹ãããå ´åã«ããã¤ãã¼ãå ã§é©åãªã¢ã¯ã»ã¹è¨±å¯ãä»ä¸ããã¦ããªããã°ãã¢ã¯ã»ã¹ã§ãã¾ããã
ã¾ããéçºè ã¯ããããã種é¡ã®ã«ã¹ã¿ã ãã¼ã¿ããã¤ãã¼ãå ã«é ç½®ã§ãã¾ãããã¨ãã°ãGoogleã®ã¢ã¯ã»ã¹ãã¼ã¯ã³ã¯è¤æ°ã®ã¢ããªã±ã¼ã·ã§ã³ï¼APIï¼ã«ã¢ã¯ã»ã¹æ¨©ãä»ä¸ã§ãããããã®è³æ ¼æ å ±ã¯ãã¹ã¦1ã¤ã®ã¢ã¯ã»ã¹ãã¼ã¯ã³ã§æå®ããã¾ãã
ã¢ã¯ã»ã¹ãã¼ã¯ã³ã®ã¿ã¤ãã¯ãWebãµã¤ããã¨ã«ç°ãªãã¾ãããã¨ãã°ãFacebookã¯4ã¤ã®ã¢ã¯ã»ã¹ãã¼ã¯ã³ã¿ã¤ããæä¾ãã¦ãã¾ããããã«æ°åã¿ã¤ããä»ã®ãµã¤ãã§æä¾ããã¦ãã¾ãã
ããããã©ãã ãå¤ãã®ãã¼ã¿ãå«ãã ã¨ããã§ãã¢ã¯ã»ã¹ãã¼ã¯ã³ãé·ããªãããã§ã¯ããã¾ããããã¨ãã°ãJSON Web Tokenï¼JWTï¼ã¯ã3ã¤ã®Base64-URLæååã§æ§æããã¾ãããã®æ®µè½ãããçãã®ã§ãã
ã¢ã¯ã»ã¹ãã¼ã¯ã³ã®ä»çµã¿
ã¦ã¼ã¶ã¼ãèªåã®ã¢ã¯ã»ã¹ã³ã¼ããè¨è¿°ãããã¨ã¯ããã¾ããããµã¼ãã¼ã¯ããã¤ã¹ã¨éä¿¡ãããã¹ã¦ã®ä½æ¥ã¯æ°åã§è¡ããã¾ãã
以ä¸ã®äºæ¸¬å¯è½ãªä¸é£ã®æç¶ããè¡ããã¾ãã
- ãã°ã¤ã³ï¼æ¢ç¥ã®ã¦ã¼ã¶ã¼åã¨ãã¹ã¯ã¼ãã使ç¨ãã¦ãã¢ã¤ãã³ãã£ãã£ã証æãã¾ãã
- æ¤è¨¼ï¼ãµã¼ãã¼ããã¼ã¿ãèªè¨¼ãããã¼ã¯ã³ãçºè¡ãã¾ãã
- æ ¼ç´ï¼ãã¼ã¯ã³ããã©ã¦ã¶ã«éä¿¡ãããä¿åããã¾ãã
- éä¿¡ï¼ã¦ã¼ã¶ã¼ããµã¼ãã¼ä¸ã®æ°ãããã¼ã¿ã«ã¢ã¯ã»ã¹ãããã³ã«ããã¼ã¯ã³ã®æ¤è¨¼ãåã³è¡ããã¾ãã
- åé¤ï¼ã»ãã·ã§ã³ãçµäºããã¨ããã¼ã¯ã³ã¯ç ´æ£ããã¾ãã
ã¢ã¯ã»ã¹ãã¼ã¯ã³ã¯ãã·ã³ã°ã«ãµã¤ã³ãªã³ï¼SSOï¼ã«ä½¿ç¨ãããã¨ãå¯è½ã§ãããã®ã¨ãããããµã¤ãããã®è³æ ¼æ å ±ããå¥ã®ãµã¤ãã¸ã®ã¨ã³ããªã«ä½¿ç¨ããããéµãã«ãªãã¾ãã以ä¸ã®æé ã«å¾ãã¾ãã
- èªå¯ï¼ãããµã¤ãããã®è³æ ¼æ å ±ãå¥ã®ãµã¤ãã¸ã®ã¨ã³ããªã«ä½¿ç¨ãããã¨ã«åæãã¾ãã
- æ¥ç¶ï¼ç¬¬1ã®ãµã¤ãã第2ã®ãµã¤ãã«æ¥ç¶ããæ¯æ´ãæ±ãã¾ãã第2ã®ãµã¤ããã¢ã¯ã»ã¹ãã¼ã¯ã³ãä½æãã¾ãã
- æ ¼ç´ï¼ã¢ã¯ã»ã¹ãã¼ã¯ã³ããã©ã¦ã¶ã«ä¿åããã¾ãã
- ã¨ã³ããªï¼ç¬¬2ã®ãµã¤ãããã®ã¢ã¯ã»ã¹ãã¼ã¯ã³ãã第1ã®ãµã¤ãã¸ã®ã¨ã³ããªãæä¾ãã¾ãã
SSOã®ãªã¯ã¨ã¹ãã¯ããã«æéåãã«ãªãã¾ãã以åã«ã解説ãã¾ããããã»ã¨ãã©ã®ãªã¯ã¨ã¹ãã¯ç´10åã§æéåãã«ãªãã¾ããããã60ç§ã§ããã»ã¹ãéãããªã¯ã¨ã¹ããããã¾ãã
ã¢ã¯ã»ã¹ãã¼ã¯ã³ã®ä¿è·
ã¢ã¯ã»ã¹ãã¼ã¯ã³ã¯ãã¤ã³ã¿ã¼ãããã®ãªã¼ãã³ã¹ãã¼ã¹ã移åããéã«ã¯ä¿è·ãããå¿ è¦ãããã¾ããä¼æ¥ãæå·åãä¿è·ãããéä¿¡ãã£ãã«ã使ç¨ããªããã°ããµã¼ããã¼ãã£ããã¼ã¯ã³ãåå¾ã§ããããã«ãªãããã®ãããªå ´åã«ã¯æ©å¯ãã¼ã¿ã¸ã®ä¸æ£ã¢ã¯ã»ã¹ãå¯è½ã«ãªãã¾ããã¤ã¾ããç´°å¿ã®æ³¨æãæããã¨ãéè¦ãªã®ã§ãã
ã¾ããã»ã¨ãã©ã®ã¢ã¯ã»ã¹ãã¼ã¯ã³ã«ã¯ãæå¹æéãããã¾ãããã®ç°¡åãªæé ã«ãã£ã¦ãã¦ã¼ã¶ã¼ããªã³ã©ã¤ã³ã§ã¢ã¯ãã£ãã§ãããã¨ãWebãµã¤ãã確èªã§ãã大è¦æ¨¡ãªè¤è£½ãåé¤ãåé¿ããä¸ã§å½¹ç«ã¡ã¾ããæå¹æéã¯ä¼æ¥ã«ãã£ã¦ç°ãªãã¾ãã
Oktaã¯ãå ç¢ãªã·ã¹ãã ã«ããä¿åä¸/転éä¸ã®ãã¼ã¿ãä¿è·ããã客æ§ãããã«ã¼ãé ãããããã«åãã¹ãæé ãç解ããããã®ãæä¼ããæä¾ãã¦ãã¾ããã¾ããOktaã®ãã¼ã«ã使ç¨ãããã¨ã§ãã客æ§ã¯ãã¼ã¿ãç°¡åãã¤è¿ éã«æå·åã§ãã¾ãã詳ããã¯ãåãåãããã ããã
åèæç®
Using OAuth 2.0 to Access Google APIsï¼2020å¹´12æãGoogle Identityï¼Â
Access Tokensï¼Facebook for Developersï¼Â
What Is OAuth? How the Open Authorization Framework Worksï¼2019å¹´9æãCSOï¼
Â