ืžื“ืจื™ืš ืžืฆื•ื™ืจ ืœ-OAuth ื•-OpenID Connect

ื”ืขืจื”. ืชืจื’ื•ื: ื”ืžืืžืจ ื”ื ื”ื“ืจ ื”ื–ื” ืฉืœ Okta ืžืกื‘ื™ืจ ื›ื™ืฆื“ OAuth ื•- OIDC (OpenID Connect) ืคื•ืขืœื™ื ื‘ืฆื•ืจื” ืคืฉื•ื˜ื” ื•ื‘ืจื•ืจื”. ื™ื“ืข ื–ื” ื™ื”ื™ื” ืฉื™ืžื•ืฉื™ ืœืžืคืชื—ื™ื, ืžื ื”ืœื™ ืžืขืจื›ื•ืช ื•ืืคื™ืœื• "ืžืฉืชืžืฉื™ื ืจื’ื™ืœื™ื" ืฉืœ ืืคืœื™ืงืฆื™ื•ืช ืื™ื ื˜ืจื ื˜ ืคื•ืคื•ืœืจื™ื•ืช, ืฉื›ื›ืœ ื”ื ืจืื” ื’ื ืžื—ืœื™ืคื™ื ื ืชื•ื ื™ื ืกื•ื“ื™ื™ื ืขื ืฉื™ืจื•ืชื™ื ืื—ืจื™ื.

ื‘ืชืงื•ืคืช ื”ืื‘ืŸ ืฉืœ ื”ืื™ื ื˜ืจื ื˜, ืฉื™ืชื•ืฃ ืžื™ื“ืข ื‘ื™ืŸ ืฉื™ืจื•ืชื™ื ื”ื™ื” ืงืœ. ืคืฉื•ื˜ ื ืชืช ืืช ืคืจื˜ื™ ื”ื›ื ื™ืกื” ื•ื”ืกื™ืกืžื” ืฉืœืš ืžืฉื™ืจื•ืช ืื—ื“ ืœืื—ืจ, ื›ืš ืฉื”ื•ื ื ื›ื ืก ืœื—ืฉื‘ื•ืŸ ืฉืœืš ื•ืงื™ื‘ืœ ื›ืœ ืžื™ื“ืข ืฉื”ื•ื ืฆืจื™ืš.

ืžื“ืจื™ืš ืžืฆื•ื™ืจ ืœ-OAuth ื•-OpenID Connect
"ืชืŸ ืœื™ ืืช ื—ืฉื‘ื•ืŸ ื”ื‘ื ืง ืฉืœืš." "ืื ื—ื ื• ืžื‘ื˜ื™ื—ื™ื ืฉื”ื›ืœ ื™ื”ื™ื” ื‘ืกื“ืจ ืขื ื”ืกื™ืกืžื” ื•ื”ื›ืกืฃ. ื–ื” ื›ื ื”, ื›ื ื”!" *ื—ื™ ื—ื™*

ื—ึฒืจึธื“ึธื”! ืืฃ ืื—ื“ ืœื ืฆืจื™ืš ืœื“ืจื•ืฉ ืžืžืฉืชืžืฉ ืœืฉืชืฃ ืฉื ืžืฉืชืžืฉ ื•ืกื™ืกืžื”, ืื™ืฉื•ืจื™ื, ืขื ืฉื™ืจื•ืช ืื—ืจ. ืื™ืŸ ืขืจื•ื‘ื” ืฉื”ืืจื’ื•ืŸ ืฉืขื•ืžื“ ืžืื—ื•ืจื™ ืฉื™ืจื•ืช ื–ื” ื™ืฉืžื•ืจ ืขืœ ืื‘ื˜ื—ืช ื”ื ืชื•ื ื™ื ื•ืœื ื™ืืกื•ืฃ ืžื™ื“ืข ืื™ืฉื™ ื™ื•ืชืจ ืžื”ื ื“ืจืฉ. ื–ื” ืื•ืœื™ ื ืฉืžืข ืžื˜ื•ืจืฃ, ืื‘ืœ ืืคืœื™ืงืฆื™ื•ืช ืžืกื•ื™ืžื•ืช ืขื“ื™ื™ืŸ ืžืฉืชืžืฉื•ืช ื‘ืชืจื’ื•ืœ ื”ื–ื”!

ื›ื™ื•ื ืงื™ื™ื ืชืงืŸ ื‘ื•ื“ื“ ื”ืžืืคืฉืจ ืœืฉื™ืจื•ืช ืื—ื“ ืœื”ืฉืชืžืฉ ื‘ืฆื•ืจื” ืžืื•ื‘ื˜ื—ืช ื‘ื ืชื•ื ื™ื ืฉืœ ืื—ืจ. ืœืžืจื‘ื” ื”ืฆืขืจ, ืชืงื ื™ื ื›ืืœื” ืžืฉืชืžืฉื™ื ื‘ื”ืจื‘ื” ื–'ืจื’ื•ืŸ ื•ืžื•ื ื—ื™ื, ืžื” ืฉืžืงืฉื” ืขืœ ื”ื”ื‘ื ื” ืฉืœื”ื. ืžื˜ืจืช ื”ื—ื•ืžืจ ื”ื–ื” ื”ื™ื ืœื”ืกื‘ื™ืจ ืื™ืš ื”ื ืคื•ืขืœื™ื ื‘ืืžืฆืขื•ืช ืื™ื•ืจื™ื ืคืฉื•ื˜ื™ื (ื”ืื ืืชื” ื—ื•ืฉื‘ ืฉื”ืฆื™ื•ืจื™ื ืฉืœื™ ื“ื•ืžื™ื ืœื”ื˜ื—ืช ื™ืœื“ื™ื? ื ื• ื˜ื•ื‘!).

ืžื“ืจื™ืš ืžืฆื•ื™ืจ ืœ-OAuth ื•-OpenID Connect

ืื’ื‘, ื”ืžื“ืจื™ืš ื”ื–ื” ื–ืžื™ืŸ ื’ื ื‘ืคื•ืจืžื˜ ื•ื™ื“ืื•:

ื’ื‘ื™ืจื•ืชื™ื™ ื•ืจื‘ื•ืชื™ื™, ื‘ืจื•ื›ื™ื ื”ื‘ืื™ื: OAuth 2.0

OAuth 2.0 ื”ื•ื ืชืงืŸ ืื‘ื˜ื—ื” ื”ืžืืคืฉืจ ืœืืคืœื™ืงืฆื™ื” ืื—ืช ืœืงื‘ืœ ื”ืจืฉืื” ืœื’ืฉืช ืœืžื™ื“ืข ื‘ืืคืœื™ืงืฆื™ื” ืื—ืจืช. ืจืฆืฃ ืฉืœื‘ื™ื ืœืžืชืŸ ื”ื™ืชืจ [ืจึฐืฉืื•ึผืช] (ืื• ื”ึทืกื›ึผึธืžึธื” [ื”ึทืกื›ึผึธืžึธื”]) ืžืชืงืฉืจื™ื ืœืขืชื™ื ืงืจื•ื‘ื•ืช ื”ืจืฉืื” [ื”ืจืฉืื”] ืื• ืืคื™ืœื• ื”ืจืฉืื” ืžืืฆื™ืœื” [ื”ืจืฉืื” ืžื•ืืฆืœืช]. ืขื ืชืงืŸ ื–ื”, ืืชื” ืžืืคืฉืจ ืœืืคืœื™ืงืฆื™ื” ืœืงืจื•ื ื ืชื•ื ื™ื ืื• ืœื”ืฉืชืžืฉ ื‘ืคื•ื ืงืฆื™ื•ืช ืฉืœ ืืคืœื™ืงืฆื™ื” ืื—ืจืช ื‘ืฉืžืš ืžื‘ืœื™ ืœืชืช ืœื” ืืช ื”ืกื™ืกืžื” ืฉืœืš. ืžืขืžื“!

ื›ื“ื•ื’ืžื”, ื ื ื™ื— ืฉืืชื” ืžื’ืœื” ืืชืจ ื‘ืฉื "Unlucky Pun of the Day" [ืžืฉื—ืง ืžื™ืœื™ื ื ื•ืจื ืฉืœ ื”ื™ื•ื] ื•ื”ื—ืœื™ื˜ ืœื”ื™ืจืฉื ืืœื™ื• ื›ื“ื™ ืœืงื‘ืœ ืžืฉื—ืงื™ ืžื™ืœื™ื ื™ื•ืžื™ื•ืžื™ื™ื ื‘ืฆื•ืจืช ื”ื•ื“ืขื•ืช ื˜ืงืกื˜ ื‘ื˜ืœืคื•ืŸ. ืžืื•ื“ ืื”ื‘ืช ืืช ื”ืืชืจ, ื•ื”ื—ืœื˜ืช ืœืฉืชืฃ ืื•ืชื• ืขื ื›ืœ ื”ื—ื‘ืจื™ื ืฉืœืš. ืื—ืจื™ ื”ื›ืœ, ื›ื•ืœื ืื•ื”ื‘ื™ื ืžืฉื—ืงื™ ืžื™ืœื™ื ืžืคื—ื™ื“ื™ื, ื ื›ื•ืŸ?

ืžื“ืจื™ืš ืžืฆื•ื™ืจ ืœ-OAuth ื•-OpenID Connect
"ืžืฉื—ืง ืžื™ืœื™ื ืžืฆืขืจ ืฉืœ ื”ื™ื•ื: ืฉืžืขืช ืขืœ ื”ื‘ื—ื•ืจ ืฉืื™ื‘ื“ ืืช ื”ื—ืฆื™ ื”ืฉืžืืœื™ ืฉืœ ื’ื•ืคื•? ืขื›ืฉื™ื• ื”ื•ื ืชืžื™ื“ ืฆื•ื“ืง!" (ืชืจื’ื•ื ืžืฉื•ืขืจ, ื›ื™ ืœืžืงื•ืจ ื™ืฉ ืžืฉื—ืง ืžื™ืœื™ื ืžืฉืœื• - ื‘ืขืจืš ืชืจื’ื•ื)

ื‘ืจื•ืจ ืฉื›ืชื™ื‘ื” ืœื›ืœ ืื“ื ืžืจืฉื™ืžืช ืื ืฉื™ ื”ืงืฉืจ ื”ื™ื ืœื ืื•ืคืฆื™ื”. ื•ืื ืืชื” ืืคื™ืœื• ืงืฆืช ื›ืžื•ื ื™, ืื– ืชืขืฉื” ืžืืžืฆื™ื ืจื‘ื™ื ื›ื“ื™ ืœื”ื™ืžื ืข ืžืขื‘ื•ื“ื” ืžื™ื•ืชืจืช. ืœืžืจื‘ื” ื”ืžื–ืœ, ืžืฉื—ืง ื”ืžื™ืœื™ื ื”ื ื•ืจื ืฉืœ ื”ื™ื•ื ื™ื›ื•ืœ ืœื”ื–ืžื™ืŸ ืืช ื›ืœ ื”ื—ื‘ืจื™ื ืฉืœืš ืœื‘ื“! ืœืฉื ื›ืš, ืืชื” ืจืง ืฆืจื™ืš ืœืคืชื•ื— ื’ื™ืฉื” ืœืžื™ื™ืœ ืฉืœ ืื ืฉื™ ื”ืงืฉืจ ืฉืœืš - ื”ืืชืจ ืขืฆืžื• ื™ืฉืœื— ืœื”ื ื”ื–ืžื ื•ืช (ื—ื•ืงื™ OAuth)!

ืžื“ืจื™ืš ืžืฆื•ื™ืจ ืœ-OAuth ื•-OpenID Connect
"ื›ื•ืœื ืื•ื”ื‘ื™ื ืžืฉื—ืงื™ ืžื™ืœื™ื! - ื›ื‘ืจ ืžื—ื•ื‘ืจ? "ื”ืื ืชืจืฆื” ืœืืคืฉืจ ืœืืชืจ Terrible Pun of the Day ืœื’ืฉืช ืœืจืฉื™ืžืช ืื ืฉื™ ื”ืงืฉืจ ืฉืœืš? - ืชื•ื“ื”! ืžืขืชื” ื•ืื™ืœืš ื ืฉืœื— ืชื–ื›ื•ืจื•ืช ื‘ื›ืœ ื™ื•ื ืœื›ืœ ืžื™ ืฉืืชื” ืžื›ื™ืจ, ืขื“ ืงืฅ ื”ื™ืžื™ื! ืืชื” ื”ื—ื‘ืจ ื”ื›ื™ ื˜ื•ื‘!"

  1. ื‘ื—ืจ ืืช ืฉื™ืจื•ืช ื”ื“ื•ื"ืœ ืฉืœืš.
  2. ื‘ืžื™ื“ืช ื”ืฆื•ืจืš, ืขื‘ื•ืจ ืืœ ืืชืจ ื”ื“ื•ืืจ ื•ื”ื™ื›ื ืก ืœื—ืฉื‘ื•ื ืš.
  3. ืชืŸ ืœ-Trible Pun of the Day ื”ืจืฉืื” ืœื’ืฉืช ืœืื ืฉื™ ื”ืงืฉืจ ืฉืœืš.
  4. ื—ื–ื•ืจ ืœืืชืจ ืžืฉื—ืง ื”ืžื™ืœื™ื ื”ื ื•ืจื ืฉืœ ื”ื™ื•ื.

ื‘ืžืงืจื” ืฉืชืฉื ื” ืืช ื“ืขืชืš, ื™ื™ืฉื•ืžื™ื ื”ืžืฉืชืžืฉื™ื ื‘-OAuth ืžืกืคืงื™ื ื’ื ื“ืจืš ืœื‘ื˜ืœ ื’ื™ืฉื”. ืœืื—ืจ ืฉืชื—ืœื™ื˜ ืฉืื™ื ืš ืจื•ืฆื” ื™ื•ืชืจ ืœืฉืชืฃ ืื ืฉื™ ืงืฉืจ ืขื Terrible Pun of the Day, ืชื•ื›ืœ ืœื”ื™ื›ื ืก ืœืืชืจ ื”ื“ื•ืืจ ื•ืœื”ืกื™ืจ ืืช ืืชืจ ืžืฉื—ืง ื”ืžื™ืœื™ื ืžืจืฉื™ืžืช ื”ื™ื™ืฉื•ืžื™ื ื”ืžื•ืจืฉื™ื.

ื–ืจื™ืžืช OAuth

ื–ื” ืขืชื” ืขื‘ืจื ื• ืืช ืžื” ืฉื ืงืจื ื‘ื“ืจืš ื›ืœืœ ื–ึฐืจึดื™ืžึธื” [ื–ึฐืจึดื™ืžึธื”] OAuth. ื‘ื“ื•ื’ืžื” ืฉืœื ื•, ื–ืจื™ืžื” ื–ื• ืžื•ืจื›ื‘ืช ืžืฉืœื‘ื™ื ื’ืœื•ื™ื™ื, ื•ื›ืŸ ืžืกืคืจ ืฉืœื‘ื™ื ื‘ืœืชื™ ื ืจืื™ื, ืฉื‘ื”ื ืฉื ื™ ืฉื™ืจื•ืชื™ื ืžืกื›ื™ืžื™ื ืขืœ ื”ื—ืœืคืช ืžื™ื“ืข ืžืื•ื‘ื˜ื—ืช. ื”ื“ื•ื’ืžื” ื”ืงื•ื“ืžืช ืฉืœ Terrible Pun of the Day ืžืฉืชืžืฉืช ื‘ื–ืจื™ืžืช ื”-OAuth 2.0 ื”ื ืคื•ืฆื” ื‘ื™ื•ืชืจ, ื”ื™ื“ื•ืขื” ื›ื–ืจื™ืžืช "ืงื•ื“ ื”ื”ืจืฉืื”". [ื–ืจื™ืžืช "ืงื•ื“ ื”ืจืฉืื”"].

ืœืคื ื™ ืฉื ืฆืœื•ืœ ืœืคืจื˜ื™ื ืฉืœ ืื•ืคืŸ ื”ืคืขื•ืœื” ืฉืœ OAuth, ื‘ื•ืื• ื ื“ื‘ืจ ืขืœ ื”ืžืฉืžืขื•ืช ืฉืœ ื›ืžื” ืžื•ื ื—ื™ื:

  • ื‘ืขืœ ืžืฉืื‘ื™ื:

    ืžื“ืจื™ืš ืžืฆื•ื™ืจ ืœ-OAuth ื•-OpenID Connect

    ื–ื” ืืชื”! ืืชื” ื”ื‘ืขืœื™ื ืฉืœ ื”ืื™ืฉื•ืจื™ื ืฉืœืš, ื”ื ืชื•ื ื™ื ืฉืœืš ื•ืฉื•ืœื˜ ื‘ื›ืœ ื”ืคืขื™ืœื•ื™ื•ืช ืฉืขืฉื•ื™ื•ืช ืœื”ืชื‘ืฆืข ื‘ื—ืฉื‘ื•ื ื•ืช ืฉืœืš.

  • ืœืงื•ื—:

    ืžื“ืจื™ืš ืžืฆื•ื™ืจ ืœ-OAuth ื•-OpenID Connect

    ืืคืœื™ืงืฆื™ื” (ืœื“ื•ื’ืžื”, ืฉื™ืจื•ืช ืžืฉื—ืง ื”ืžื™ืœื™ื ื”ื ื•ืจื ืฉืœ ื”ื™ื•ื) ืฉืจื•ืฆื” ืœื’ืฉืช ืื• ืœื‘ืฆืข ืคืขื•ืœื•ืช ืžืกื•ื™ืžื•ืช ื‘ืฉื ื‘ืขืœ ืžืฉืื‘ื™ื'ื.

  • ืฉืจืช ื”ืจืฉืื”:

    ืžื“ืจื™ืš ืžืฆื•ื™ืจ ืœ-OAuth ื•-OpenID Connect

    ื”ืืคืœื™ืงืฆื™ื” ืฉื™ื•ื“ืขืช ื‘ืขืœ ืžืฉืื‘ื™ื'ื ื•ื‘ื• u ื‘ืขืœ ืžืฉืื‘ื™ืื™ืฉ ื›ื‘ืจ ื—ืฉื‘ื•ืŸ.

  • ืฉืจืช ืžืฉืื‘ื™ื:

    ืžื“ืจื™ืš ืžืฆื•ื™ืจ ืœ-OAuth ื•-OpenID Connect

    ืžืžืฉืง ืชื›ื ื•ืช ื™ื™ืฉื•ืžื™ื (API) ืื• ืฉื™ืจื•ืช ื–ื” ืœืงื•ื— ืจื•ืฆื” ืœื”ืฉืชืžืฉ ืžื˜ืขื ื‘ืขืœ ืžืฉืื‘ื™ื'ื.

  • ื”ืคื ื™ื™ื” ืžื—ื“ืฉ ืฉืœ URI:

    ืžื“ืจื™ืš ืžืฆื•ื™ืจ ืœ-OAuth ื•-OpenID Connect

    ื”ืงื™ืฉื•ืจ ืฉ ืฉืจืช ื”ืจืฉืื” ื™ืคื ื” ืžื—ื“ืฉ ื‘ืขืœ ืžืฉืื‘ื™ื'ื•ืื—ืจื™ ืžืชืŸ ืจืฉื•ืช ืœืงื•ื—'ื‘ึผึฐ. ืœืคืขืžื™ื ื–ื” ืžื›ื•ื ื” "ื›ืชื•ื‘ืช ื”ืืชืจ ืœื”ืชืงืฉืจื•ืช ื—ื•ื–ืจืช".

  • ืกื•ื’ ืชื’ื•ื‘ื”:

    ืžื“ืจื™ืš ืžืฆื•ื™ืจ ืœ-OAuth ื•-OpenID Connect

    ืกื•ื’ ื”ืžื™ื“ืข ื”ืฆืคื•ื™ ืœื”ืชืงื‘ืœ ืœืงื•ื—. ื”ื ืคื•ืฅ ื‘ื™ื•ืชืจ ืกื•ื’ ืชื’ื•ื‘ื”'ืื•ื”ื ื–ื” ื”ืงื•ื“, ื›ืœื•ืžืจ ืœืงื•ื— ืžืฆืคื” ืœืงื‘ืœ ืงื•ื“ ืื™ืžื•ืช.

  • ื”ื™ืงืฃ:

    ืžื“ืจื™ืš ืžืฆื•ื™ืจ ืœ-OAuth ื•-OpenID Connect

    ื–ื”ื• ืชื™ืื•ืจ ืžืคื•ืจื˜ ืฉืœ ื”ื”ืจืฉืื•ืช ื”ื ื“ืจืฉื•ืช ืœืงื•ื—'y, ื›ื’ื•ืŸ ื’ื™ืฉื” ืœื ืชื•ื ื™ื ืื• ื‘ื™ืฆื•ืข ืคืขื•ืœื•ืช ืžืกื•ื™ืžื•ืช.

  • ื”ืกื›ืžื”:

    ืžื“ืจื™ืš ืžืฆื•ื™ืจ ืœ-OAuth ื•-OpenID Connect

    ืฉืจืช ื”ืจืฉืื” ืœื•ืงื— ืกืงื•ืคืกื‘ื™ืงืฉ ืœืงื•ื—ืื”, ื•ืฉื•ืืœ ื‘ืขืœ ืžืฉืื‘ื™ืื, ื”ืื ื”ื•ื ืžื•ื›ืŸ ืœืกืคืง ืœืงื•ื—ื™ืฉ ืืช ื”ื”ืจืฉืื•ืช ื”ืžืชืื™ืžื•ืช.

  • ื–ื™ื”ื•ื™ ื”ืœืงื•ื—:

    ืžื“ืจื™ืš ืžืฆื•ื™ืจ ืœ-OAuth ื•-OpenID Connect

    ืžื–ื”ื” ื–ื” ืžืฉืžืฉ ืœื–ื™ื”ื•ื™ ืœืงื•ื—'ื ืขืœ ืฉืจืช ื”ืจืฉืื”ื”.

  • ืกื•ื“ ื”ืœืงื•ื—:

    ืžื“ืจื™ืš ืžืฆื•ื™ืจ ืœ-OAuth ื•-OpenID Connect

    ื–ื• ื”ืกื™ืกืžื” ืฉืจืง ื™ื“ื•ืขื” ืœืงื•ื—ืืชื” ื• ืฉืจืช ื”ืจืฉืื”'ื‘ึผึฐ. ื–ื” ืžืืคืฉืจ ืœื”ื ืœืฉืชืฃ ืžื™ื“ืข ื‘ืื•ืคืŸ ืคืจื˜ื™.

  • ืงื•ื“ ืื™ืžื•ืช:

    ืžื“ืจื™ืš ืžืฆื•ื™ืจ ืœ-OAuth ื•-OpenID Connect

    ืงื•ื“ ื–ืžื ื™ ืขื ืชืงื•ืคืช ืชื•ืงืฃ ืงืฆืจื”, ืืฉืจ ืœืงื•ื— ืžืกืคืง ืฉืจืช ื”ืจืฉืื”'ื™ ื‘ืชืžื•ืจื” ืœ ืืกื™ืžื•ืŸ ื’ื™ืฉื”.

  • ืืกื™ืžื•ืŸ ื’ื™ืฉื”:

    ืžื“ืจื™ืš ืžืฆื•ื™ืจ ืœ-OAuth ื•-OpenID Connect

    ื”ืžืคืชื— ืฉื”ืœืงื•ื— ื™ืฉืชืžืฉ ื‘ื• ื›ื“ื™ ืœืชืงืฉืจ ืื™ืชื• ืฉืจืช ืžืฉืื‘ื™ื'ืื•ืž. ืžืขื™ืŸ ืชื’ ืื• ื›ืจื˜ื™ืก ืžืคืชื— ื”ืžืกืคืง ืœืงื•ื—ื™ืฉ ืจืฉื•ืช ืœื‘ืงืฉ ื ืชื•ื ื™ื ืื• ืœื‘ืฆืข ืคืขื•ืœื•ืช ืขืœื™ื”ื ืฉืจืช ืžืฉืื‘ื™ืื‘ืฉืžืš.

ืฉื™ื ืœื‘: ืœืคืขืžื™ื ืฉืจืช ื”ื”ืจืฉืื•ืช ื•ืฉืจืช ื”ืžืฉืื‘ื™ื ื”ื ืื•ืชื• ืฉืจืช. ืขื ื–ืืช, ื‘ืžืงืจื™ื ืžืกื•ื™ืžื™ื, ืืœื• ืขืฉื•ื™ื™ื ืœื”ื™ื•ืช ืฉืจืชื™ื ืฉื•ื ื™ื, ื’ื ืื ืื™ื ื ืฉื™ื™ื›ื™ื ืœืื•ืชื• ืืจื’ื•ืŸ. ืœื“ื•ื’ืžื”, ืฉืจืช ื”ื”ืจืฉืื•ืช ืขืฉื•ื™ ืœื”ื™ื•ืช ืฉื™ืจื•ืช ืฉืœ ืฆื“ ืฉืœื™ืฉื™ ืžื”ื™ืžืŸ ืขืœ ื™ื“ื™ ืฉืจืช ื”ืžืฉืื‘ื™ื.

ื›ืขืช, ืœืื—ืจ ืฉื›ื™ืกื™ื ื• ืืช ืžื•ืฉื’ื™ ื”ืœื™ื‘ื” ืฉืœ OAuth 2.0, ื‘ื•ืื• ื ื—ื–ื•ืจ ืœื“ื•ื’ืžื ืฉืœื ื• ื•ื ืกืชื›ืœ ืžืงืจื•ื‘ ืขืœ ืžื” ืฉืงื•ืจื” ื‘ื–ืจื™ืžืช OAuth.

ืžื“ืจื™ืš ืžืฆื•ื™ืจ ืœ-OAuth ื•-OpenID Connect

  1. ืืชื”, ื‘ืขืœ ืžืฉืื‘ื™ื, ืืชื” ืจื•ืฆื” ืœืกืคืง ืืช ืฉื™ืจื•ืช ืžืฉื—ืง ื”ืžื™ืœื™ื ื”ื ื•ืจื ืฉืœ ื”ื™ื•ื (ืœืงื•ื—y) ื’ื™ืฉื” ืœืื ืฉื™ ื”ืงืฉืจ ืฉืœืš ื›ื“ื™ ืฉื™ื•ื›ืœื• ืœืฉืœื•ื— ื”ื–ืžื ื•ืช ืœื›ืœ ื”ื—ื‘ืจื™ื ืฉืœืš.
  2. ืœืงื•ื— ืžืคื ื” ืืช ื”ื“ืคื“ืคืŸ ืœื“ืฃ ืฉืจืช ื”ืจืฉืื”'ื ื•ืœื›ืœื•ืœ ื‘ืฉืื™ืœืชื” ื–ื™ื”ื•ื™ ื”ืœืงื•ื—, ื”ืคื ื™ื™ื” ืžื—ื“ืฉ ืฉืœ URI, ืกื•ื’ ืชื’ื•ื‘ื” ื•ืื—ื“ ืื• ื™ื•ืชืจ ืกืงื•ืคืก (ื”ืจืฉืื•ืช) ืฉื”ื•ื ืฆืจื™ืš.
  3. ืฉืจืช ื”ืจืฉืื” ืžืืžืช ืื•ืชืš, ืžื‘ืงืฉ ืฉื ืžืฉืชืžืฉ ื•ืกื™ืกืžื” ื‘ืžื™ื“ืช ื”ืฆื•ืจืš.
  4. ืฉืจืช ื”ืจืฉืื” ืžืฆื™ื’ ื˜ื•ืคืก ื”ืกื›ืžื” (ืื™ืฉื•ืจื™ื) ืขื ืจืฉื™ืžื” ืฉืœ ื›ื•ืœื ืกืงื•ืคืกื‘ื™ืงืฉ ืœืงื•ื—'ืื•ืž. ืืชื” ืžืกื›ื™ื ืื• ืžืกืจื‘.
  5. ืฉืจืช ื”ืจืฉืื” ืžืคื ื” ืื•ืชืš ืœืืชืจ ืœืงื•ื—'ื, ื‘ืืžืฆืขื•ืช ื”ืคื ื™ื™ื” ืžื—ื“ืฉ ืฉืœ URI ืขื ืงื•ื“ ืื™ืžื•ืช (ืงื•ื“ ืื™ืžื•ืช).
  6. ืœืงื•ื— ืžืชืงืฉืจ ื™ืฉื™ืจื•ืช ืขื ืฉืจืช ื”ืจืฉืื”'ืื•ื”ื (ืขื•ืงืฃ ืืช ื”ื“ืคื“ืคืŸ ื‘ืขืœ ืžืฉืื‘ื™ื'ื) ื•ืฉื•ืœื— ื‘ื‘ื˜ื—ื” ื–ื™ื”ื•ื™ ื”ืœืงื•ื—, ืกื•ื“ ื”ืœืงื•ื— ะธ ืงื•ื“ ืื™ืžื•ืช.
  7. ืฉืจืช ื”ืจืฉืื” ื‘ื•ื“ืง ืืช ื”ื ืชื•ื ื™ื ื•ืžื’ื™ื‘ ืขื ืืกื™ืžื•ืŸ ื’ื™ืฉื”'om (ืืกื™ืžื•ืŸ ื’ื™ืฉื”).
  8. ืขื›ืฉื™ื• ืœืงื•ื— ื™ื›ื•ืœ ืœื”ืฉืชืžืฉ ืืกื™ืžื•ืŸ ื’ื™ืฉื” ืœืฉืœื•ื— ื‘ืงืฉื” ืืœื™ื• ืฉืจืช ืžืฉืื‘ื™ื ื›ื“ื™ ืœืงื‘ืœ ืจืฉื™ืžื” ืฉืœ ืื ืฉื™ ืงืฉืจ.

ื–ื™ื”ื•ื™ ืœืงื•ื— ื•ืกื•ื“

ื”ืจื‘ื” ืœืคื ื™ ืฉื”ืจืฉื™ืช ืœืžืฉื—ืง ื”ืžื™ืœื™ื ื”ื ื•ืจื ืฉืœ ื”ื™ื•ื ืœื’ืฉืช ืœืื ืฉื™ ื”ืงืฉืจ ืฉืœืš, ืฉืจืช ื”ืœืงื•ื— ื•ื”ื”ืจืฉืื•ืช ื™ืฆืจื• ืงืฉืจื™ ืขื‘ื•ื“ื”. ืฉืจืช ื”ื”ืจืฉืื•ืช ื™ืฆืจ ืืช ืžื–ื”ื” ื”ืœืงื•ื— ื•ืืช ืกื•ื“ ื”ืœืงื•ื— (ื ืงืจื ืœืคืขืžื™ื App ID ะธ ืกื•ื“ ื”ืืคืœื™ืงืฆื™ื”) ื•ืฉืœื—ื• ืื•ืชื ืœืœืงื•ื— ืœื”ืžืฉืš ืื™ื ื˜ืจืืงืฆื™ื” ื‘ืชื•ืš OAuth.

ืžื“ืจื™ืš ืžืฆื•ื™ืจ ืœ-OAuth ื•-OpenID Connect
"- ืฉืœื•ื! ื”ื™ื™ืชื™ ืจื•ืฆื” ืœืขื‘ื•ื“ ืื™ืชืš! - ื‘ื˜ื—, ืื™ืŸ ื‘ืขื™ื”! ื”ื ื” ื–ื™ื”ื•ื™ ื”ืœืงื•ื— ื•ื”ืกื•ื“ ืฉืœืš!"

ื”ืฉื ืžืจืžื– ืฉืกื•ื“ ื”ืœืงื•ื— ื—ื™ื™ื‘ ืœื”ื™ืฉืžืจ ื‘ืกื•ื“ ื›ืš ืฉืจืง ื”ืœืงื•ื— ื•ืฉืจืช ื”ื”ืจืฉืื•ืช ื™ื“ืขื• ื–ืืช. ืื—ืจื™ ื”ื›ืœ, ื‘ืขื–ืจืชื• ืฉืจืช ื”ื”ืจืฉืื•ืช ืžืืฉืจ ืืช ืืžื™ืชื•ืช ื”ืœืงื•ื—.

ืื‘ืœ ื–ื” ืœื ื”ื›ืœ... ืื ื ื‘ืจื•ืš ื”ื‘ื ืœ-OpenID Connect!

OAuth 2.0 ืžื™ื•ืขื“ ืจืง ืขื‘ื•ืจ ื”ืจืฉืื” - ื›ื“ื™ ืœืกืคืง ื’ื™ืฉื” ืœื ืชื•ื ื™ื ื•ืœืคื•ื ืงืฆื™ื•ืช ืžืืคืœื™ืงืฆื™ื” ืื—ืช ืœืื—ืจืช. OpenID Connect (OIDC) ื”ื™ื ืฉื›ื‘ื” ื“ืงื” ืขืœ ื’ื‘ื™ OAuth 2.0 ืฉืžื•ืกื™ืคื” ืืช ืคืจื˜ื™ ื”ื›ื ื™ืกื” ื•ื”ืคืจื•ืคื™ืœ ืฉืœ ื”ืžืฉืชืžืฉ ืฉื ื›ื ืก ืœื—ืฉื‘ื•ืŸ. ื”ืืจื’ื•ืŸ ืฉืœ ืคื’ื™ืฉืช ื”ืชื—ื‘ืจื•ืช ืžื›ื•ื ื” ืœืขืชื™ื ืงืจื•ื‘ื•ืช ืื™ืžื•ืช [ืื™ืžื•ืช], ื•ืžื™ื“ืข ืขืœ ื”ืžืฉืชืžืฉ ื”ืžื—ื•ื‘ืจ ืœืžืขืจื›ืช (ื›ืœื•ืžืจ ื‘ืขืจืš ื‘ืขืœ ืžืฉืื‘ื™ื'ื”), - ืžื™ื“ืข ืื™ืฉื™ [ื–ื”ื•ืช]. ืื ืฉืจืช ื”ื”ืจืฉืื•ืช ืชื•ืžืš ื‘-OIDC, ื”ื•ื ืžื›ื•ื ื” ืœืคืขืžื™ื ืกืคืง ืฉืœ ื ืชื•ื ื™ื ืื™ืฉื™ื™ื [ืกืคืง ื–ื”ื•ืช]ื›ื™ ื–ื” ืžืกืคืง ืœืงื•ื—'ื™ืฉ ืžื™ื“ืข ืขืœ ื‘ืขืœ ืžืฉืื‘ื™ืื”.

OpenID Connect ืžืืคืฉืจ ืœืš ืœื™ื™ืฉื ืชืจื—ื™ืฉื™ื ืฉื‘ื”ื ื ื™ืชืŸ ืœื”ืฉืชืžืฉ ื‘ื›ื ื™ืกื” ื‘ื•ื“ื“ืช ื‘ืžืกืคืจ ื™ื™ืฉื•ืžื™ื - ื’ื™ืฉื” ื–ื• ื™ื“ื•ืขื” ื’ื ื‘ืฉื ื›ื ื™ืกื” ื™ื—ื™ื“ื” (SSO). ืœื“ื•ื’ืžื”, ืืคืœื™ืงืฆื™ื” ืขืฉื•ื™ื” ืœืชืžื•ืš ื‘ืฉื™ืœื•ื‘ SSO ืขื ืจืฉืชื•ืช ื—ื‘ืจืชื™ื•ืช ื›ืžื• ืคื™ื™ืกื‘ื•ืง ืื• ื˜ื•ื•ื™ื˜ืจ, ืžื” ืฉืžืืคืฉืจ ืœืžืฉืชืžืฉื™ื ืœื”ืฉืชืžืฉ ื‘ื—ืฉื‘ื•ืŸ ืฉื›ื‘ืจ ื™ืฉ ืœื”ื ื•ืžืขื“ื™ืคื™ื ืœื”ืฉืชืžืฉ ื‘ื•.

ืžื“ืจื™ืš ืžืฆื•ื™ืจ ืœ-OAuth ื•-OpenID Connect

ื”ื–ืจื™ืžื” (ื”ื–ืจื™ืžื”) OpenID Connect ื ืจืื™ืช ื–ื”ื” ืœืžืงืจื” ืฉืœ OAuth. ื”ื”ื‘ื“ืœ ื”ื™ื—ื™ื“ ื”ื•ื ืฉื‘ื‘ืงืฉื” ื”ืจืืฉื™ืช, ื”ื”ื™ืงืฃ ื”ืกืคืฆื™ืคื™ ื‘ื• ื ืขืฉื” ืฉื™ืžื•ืฉ ื”ื•ื openid, - ื ืœืงื•ื— ื‘ืกื•ืคื• ืฉืœ ื“ื‘ืจ ื ื”ื™ื” ื›ืžื• ืืกื™ืžื•ืŸ ื’ื™ืฉื”ื• - ืืกื™ืžื•ืŸ ืžื–ื”ื”.

ืžื“ืจื™ืš ืžืฆื•ื™ืจ ืœ-OAuth ื•-OpenID Connect

ื‘ื“ื™ื•ืง ื›ืžื• ื‘ื–ืจื™ืžืช OAuth, ืืกื™ืžื•ืŸ ื’ื™ืฉื” ื‘-OpenID Connect, ื–ื”ื• ืขืจืš ื›ืœืฉื”ื• ืฉืื™ื ื• ื‘ืจื•ืจ ืœืงื•ื—'ื‘ึผึฐ. ืžื ืงื•ื“ืช ืžื‘ื˜ ืœืงื•ื—'ื ืืกื™ืžื•ืŸ ื’ื™ืฉื” ืžื™ื™ืฆื’ ืžื—ืจื•ื–ืช ืชื•ื•ื™ื ื”ืžื•ืขื‘ืจืช ื™ื—ื“ ืขื ื›ืœ ื‘ืงืฉื” ืืœ ืฉืจืช ืžืฉืื‘ื™ื'y, ืฉืงื•ื‘ืข ืื ื”ืืกื™ืžื•ืŸ ืชืงืฃ. ืืกื™ืžื•ืŸ ืžื–ื”ื” ืžื™ื™ืฆื’ ื“ื‘ืจ ืื—ืจ ืœื’ืžืจื™.

ID Token ื”ื•ื JWT

ืืกื™ืžื•ืŸ ืžื–ื”ื” ื”ื•ื ืžื—ืจื•ื–ืช ืชื•ื•ื™ื ื‘ืคื•ืจืžื˜ ืžื™ื•ื—ื“ ื”ืžื›ื•ื ื” JSON Web Token ืื• JWT (ืœืคืขืžื™ื ืืกื™ืžื•ื ื™ JWT ืžื‘ื•ื˜ืื™ื ื›ืžื• "ืกื™ืžื ื™ื"). ืœืžืฉืงื™ืคื™ื ืžื‘ื—ื•ืฅ, JWT ืื•ืœื™ ื ืจืื” ื›ืžื• ื’'ื™ื‘ืจื™ืฉ ืœื ืžื•ื‘ืŸ, ืื‘ืœ ืœืงื•ื— ื™ื›ื•ืœ ืœื—ืœืฅ ืžื™ื“ืข ืฉื•ื ื” ืžื”-JWT, ื›ื’ื•ืŸ ืžื–ื”ื”, ืฉื ืžืฉืชืžืฉ, ื–ืžืŸ ื”ืชื—ื‘ืจื•ืช, ืชืืจื™ืš ืชืคื•ื’ื” ืืกื™ืžื•ืŸ ืžื–ื”ื”ื, ื ื•ื›ื—ื•ืชื ืฉืœ ื ื™ืกื™ื•ื ื•ืช ืœื”ืคืจื™ืข ืœ-JWT. ื ืชื•ื ื™ื ื‘ืคื ื™ื ืืกื™ืžื•ืŸ ืžื–ื”ื”ื ืงืจืื™ื ื™ื™ืฉื•ืžื™ื [ื˜ื•ืขืŸ].

ืžื“ืจื™ืš ืžืฆื•ื™ืจ ืœ-OAuth ื•-OpenID Connect

ื‘ืžืงืจื” ืฉืœ OIDC, ื™ืฉ ื’ื ื“ืจืš ืกื˜ื ื“ืจื˜ื™ืช ืœืคื™ื” ืœืงื•ื— ืขืฉื•ื™ ืœื‘ืงืฉ ืžื™ื“ืข ื ื•ืกืฃ ืขืœ ื”ืื“ื [ื–ื”ื•ืช] ืž ืฉืจืช ื”ืจืฉืื”', ืœืžืฉืœ, ื›ืชื•ื‘ืช ืื™ืžื™ื™ืœ ื‘ืืžืฆืขื•ืช ืืกื™ืžื•ืŸ ื’ื™ืฉื”.

ืœืžื™ื“ืข ื ื•ืกืฃ ืขืœ OAuth ื•-OIDC

ืื–, ืกืงืจื ื• ื‘ืงืฆืจื” ื›ื™ืฆื“ ืคื•ืขืœื™ื OAuth ื•- OIDC. ืžื•ื›ื ื™ื ืœื—ืคื•ืจ ื™ื•ืชืจ ืœืขื•ืžืง? ื”ื ื” ืžืฉืื‘ื™ื ื ื•ืกืคื™ื ืฉื™ืขื–ืจื• ืœืš ืœืœืžื•ื“ ืขื•ื“ ืขืœ OAuth 2.0 ื•-OpenID Connect:

ื›ืžื• ืชืžื™ื“, ืืชื ืžื•ื–ืžื ื™ื ืœื”ื’ื™ื‘. ื›ื“ื™ ืœื”ืชืขื“ื›ืŸ ื‘ื—ื“ืฉื•ืช ื”ืื—ืจื•ื ื•ืช ืฉืœื ื•, ื”ื™ืจืฉื ืœ ื˜ื•ื™ื˜ืจ ะธ YouTube Okta ืœืžืคืชื—ื™ื!

ื .ื‘ ืžื”ืžืชืจื’ื

ืงืจื ื’ื ื‘ื‘ืœื•ื’ ืฉืœื ื•:

ืžืงื•ืจ: www.habr.com

ื”ื•ืกืคืช ืชื’ื•ื‘ื”