ืึทืŸ ื™ืœืœื•ืกื˜ืจืึทื˜ืขื“ ื’ื™ื™ื“ ืฆื• OAuth ืื•ืŸ OpenID Connect

ื ืื˜ื™ืฅ. ื˜ืจืึทื ืกืœ.: ื“ืขื ื’ืจื•ื™ืก ืึทืจื˜ื™ืงืœ ืคื•ืŸ Okta ื“ืขืจืงืœืขืจื˜ ื•ื•ื™ OAuth ืื•ืŸ OIDC (OpenID Connect) ืึทืจื‘ืขื˜ ืื•ื™ืฃ ืึท ืคึผืฉื•ื˜ ืื•ืŸ ืงืœืึธืจ ื•ื•ืขื’. ื“ื™ ื•ื•ื™ืกืŸ ื•ื•ืขื˜ ื–ื™ื™ืŸ ื ื•ืฆื™ืง ืคึฟืึทืจ ื“ืขื•ื•ืขืœืึธืคึผืขืจืก, ืกื™ืกื˜ืขื ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจืก ืื•ืŸ ืืคื™ืœื• "ืจืขื’ื•ืœืขืจ ื ื™ืฆืขืจืก" ืคื•ืŸ ืคืึธืœืงืก ื•ื•ืขื‘ ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื–, ื•ื•ืึธืก ืจื•ื‘ึฟ ืžืกืชึผืžื ืื•ื™ืš ื•ื•ืขืงืกืœ ืงืึทื ืคืึทื“ืขื ืฉืึทืœ ื“ืึทื˜ืŸ ืžื™ื˜ ืื ื“ืขืจืข ื‘ืึทื“ื™ื ื•ื ื’ืก.

ืื™ืŸ ื“ื™ ืฉื˜ื™ื™ืŸ ืึทื’ืข ืคื•ืŸ โ€‹โ€‹ื“ื™ ืื™ื ื˜ืขืจื ืขื˜, ื™ื™ึทื ื˜ื™ื™ืœื•ื ื’ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืฆื•ื•ื™ืฉืŸ ืกืขืจื•ื•ื™ืกืขืก ืื™ื– ื’ืจื™ื ื’. ืื™ืจ ืคืฉื•ื˜ ื’ืขื’ืขื‘ืŸ ื“ื™ื™ืŸ ืœืึธื’ื™ืŸ ืื•ืŸ ืคึผืึทืจืึธืœ ืคื•ืŸ ืื™ื™ืŸ ื“ื™ื ืกื˜ ืฆื• ืื ื“ืขืจืŸ, ืึทื–ื•ื™ ืึทื– ืขืจ ืืจื™ื™ืŸ ื“ื™ื™ืŸ ื—ืฉื‘ื•ืŸ ืื•ืŸ ื‘ืืงื•ืžืขืŸ ืงื™ื™ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืขืจ ื“ืืจืฃ.

ืึทืŸ ื™ืœืœื•ืกื˜ืจืึทื˜ืขื“ ื’ื™ื™ื“ ืฆื• OAuth ืื•ืŸ OpenID Connect
"ื’ื™ื‘ ืžื™ืจ ื“ื™ื™ืŸ ื‘ืึทื ืง ื—ืฉื‘ื•ืŸ." "ืžื™ืจ ืฆื•ื–ืึธื’ ืึทื– ืึทืœืฅ ื•ื•ืขื˜ ื–ื™ื™ืŸ ื’ื•ื˜ ืžื™ื˜ ื“ื™ ืคึผืึทืจืึธืœ ืื•ืŸ ื’ืขืœื˜. ื“ืึธืก ืื™ื– ืขืจืœืขืš, ืขืจืœืขืš!" *ื”ื™ื™ ื”ื™ื™*

ื’ืจื•ื™ืœ! ืงื™ื™ื ืขืจ ื–ืึธืœ ืงื™ื™ื ืžืึธืœ ื“ืึทืจืคืŸ ืึท ื‘ืึทื ื™ืฆืขืจ ืฆื• ื˜ื™ื™ืœืŸ ืึท ื ืืžืขืŸ ืื•ืŸ ืคึผืึทืจืึธืœ, ืงืจืึทื“ืขื ื˜ืฉืึทืœื–, ืžื™ื˜ ืืŸ ืื ื“ืขืจ ื“ื™ื ืกื˜. ืขืก ืื™ื– ืงื™ื™ืŸ ื’ืึทืจืึทื ื˜ื™ืจืŸ ืึทื– ื“ื™ ืึธืจื’ืึทื ื™ื–ืึทืฆื™ืข ื”ื™ื ื˜ืขืจ ื“ืขื ื“ื™ื ืกื˜ ื•ื•ืขื˜ ื”ืึทืœื˜ืŸ ื“ื™ ื“ืึทื˜ืŸ ื–ื™ื›ืขืจ ืื•ืŸ ื•ื•ืขื˜ ื ื™ืฉื˜ ืงืœื™ื™ึทื‘ืŸ ืžืขืจ ืคึผืขืจื–ืขื ืœืขืš ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ื™ ื ื™ื™ื˜ื™ืง. ืขืก ืงืขืŸ ื’ืขื–ื•ื ื˜ ืžืขืฉื•ื’ืข, ืึธื‘ืขืจ ืขื˜ืœืขื›ืข ืึทืคึผืคึผืก ื ืึธืš ื ื•ืฆืŸ ื“ืขื ืคื™ืจื•ื ื’!

ื”ื™ื™ึทื ื˜ ืขืก ืื™ื– ืึท ืื™ื™ืŸ ื ืึธืจืžืึทืœ ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ื™ืŸ ื“ื™ื ืกื˜ ืฆื• ืกื™ืงื™ื•ืจืœื™ ื ื•ืฆืŸ ื“ื™ ื“ืึทื˜ืŸ ืคื•ืŸ ืื ื“ืขืจืŸ. ืฆื•ื ื‘ืึทื“ื•ื™ืขืจืŸ, ืึทื–ืึท ืกื˜ืึทื ื“ืึทืจื“ืก ื ื•ืฆืŸ ืึท ืคึผืœืึทืฅ ืคื•ืŸ ื–ืฉืึทืจื’ืึธืŸ ืื•ืŸ ื˜ืขืจืžื™ื ืขืŸ, ื•ื•ืึธืก ืงืึทืžืคึผืœื™ืงื™ื™ืฅ ื–ื™ื™ืขืจ ืคืืจืฉื˜ืื ื“. ื“ืขืจ ืฆื™ืœ ืคื•ืŸ ื“ืขื ืžืึทื˜ืขืจื™ืึทืœ ืื™ื– ืฆื• ื“ืขืจืงืœืขืจืŸ ื•ื•ื™ ื–ื™ื™ ืึทืจื‘ืขื˜ืŸ ืžื™ื˜ ืคึผืฉื•ื˜ ืื™ืœื•ืกื˜ืจืืฆื™ืขืก (ืฆื™ ืื™ืจ ื˜ืจืึทื›ื˜ืŸ ืึทื– ืžื™ื™ืŸ ื“ืจืึทื•ื•ื™ื ื’ืก ืจื™ื–ืขืžื‘ืึทืœ ืงื™ื ื“ืขืจ 'ืก ื“ืึทื•ื‘ื™ื ื’? ื˜ืึทืงืข ื’ืขื–ื•ื ื˜!).

ืึทืŸ ื™ืœืœื•ืกื˜ืจืึทื˜ืขื“ ื’ื™ื™ื“ ืฆื• OAuth ืื•ืŸ OpenID Connect

ื“ื•ืจืš ื“ืขื ื•ื•ืขื’, ื“ืขื ืคื™ืจืขืจ ืื™ื– ืื•ื™ืš ื‘ื ื™ืžืฆื ืื™ืŸ ื•ื•ื™ื“ืขื ืคึฟืึธืจืžืึทื˜:

ืœื™ื™ื“ื™ื– ืื•ืŸ ื“ื–ืฉืขื ื˜ืึทืœืžื™ืŸ, ื‘ืึทื’ืจื™ืกื•ื ื’: OAuth 2.0

OAuth 2.0 ืื™ื– ืึท ื–ื™ื›ืขืจื”ื™ื™ื˜ ืกื˜ืึทื ื“ืึทืจื˜ ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ื™ืŸ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ืฆื• ื‘ืึทืงื•ืžืขืŸ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืฆื• ืึทืงืกืขืก ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืื™ืŸ ืืŸ ืื ื“ืขืจ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ. ืกื™ืงื•ื•ืึทื ืก ืคื•ืŸ ืกื˜ืขืคึผืก ืคึฟืึทืจ ื™ืฉื•ื™ื ื’ ืึท ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ [ืจืฉื•ืช] (ืึธื“ืขืจ ืฆื•ืฉื˜ื™ืžืขืŸ [ื”ืกื›ืžื”]) ืึธืคื˜ ืจื•ืคืŸ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ [ืจืฉื•ืช] ืึธื“ืขืจ ืึทืคึฟื™ืœื• ื“ืขืœืึทื’ื™ื™ื˜ืึทื“ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ [ื“ืขืœืขื’ืึทื˜ืขื“ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ]. ืžื™ื˜ ื“ืขื ื ืึธืจืžืึทืœ, ืื™ืจ ืœืึธื–ืŸ ืึท ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ืฆื• ืœื™ื™ืขื ืขืŸ ื“ืึทื˜ืŸ ืึธื“ืขืจ ื ื•ืฆืŸ ื“ื™ ืคืึทื ื’ืงืฉืึทื ื– ืคื•ืŸ ืืŸ ืื ื“ืขืจ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ืคึฟืึทืจ ื“ื™ื™ืŸ ื‘ื™ื›ืึทืฃ ืึธืŸ ื’ืขื‘ืŸ ืขืก ื“ื™ื™ืŸ ืคึผืึทืจืึธืœ. ืงืœืึทืก!

ื•ื•ื™ ืึท ื‘ื™ื™ืฉืคึผื™ืœ, ืœืึธื–ืŸ ืก ื–ืึธื’ืŸ ืื™ืจ ืึทื ื˜ื“ืขืงืŸ ืึท ื•ื•ืขื‘ื–ื™ื™ื˜ืœ ื’ืขืจื•ืคึฟืŸ "ืฉืœื™ื™ืžืขืกื“ื™ืง ืคึผื•ืŸ ืคื•ืŸ ื“ืขื ื˜ืึธื’" [ืฉืจืขืงืœืขืš ืคึผื•ืŸ ืคื•ืŸ ื“ืขื ื˜ืึธื’] ืื•ืŸ ื‘ืึทืฉืœืึธืกืŸ ืฆื• ืคืึทืจืฉืจื™ื™ึทื‘ืŸ ืื•ื™ืฃ ืขืก ืื™ืŸ ืกื“ืจ ืฆื• ื‘ืึทืงื•ืžืขืŸ ื˜ืขื’ืœืขืš ื•ื•ืขืจื˜ืขืจ ืื™ืŸ ื“ื™ ืคืึธืจืขื ืคื•ืŸ ื˜ืขืงืกื˜ ืึทืจื˜ื™ืงืœืขืŸ ืื•ื™ืฃ ื“ื™ ื˜ืขืœืขืคืึธืŸ. ืื™ืจ ื˜ืึทืงืข ืœื™ื™ืงื˜ ื“ืขื ืคึผืœืึทืฅ, ืื•ืŸ ืื™ืจ ื‘ืึทืฉืœืึธืกืŸ ืฆื• ื˜ื™ื™ืœืŸ ืขืก ืžื™ื˜ ืึทืœืข ื“ื™ื™ืŸ ืคืจืขื ื“ื–. ื ืึธืš ืึทืœืข, ืึทืœืขืžืขืŸ ืœื™ื™ืงืก ืงืจื™ืคึผื™ ื•ื•ืขืจื˜ืขืจ, ืจืขื›ื˜?

ืึทืŸ ื™ืœืœื•ืกื˜ืจืึทื˜ืขื“ ื’ื™ื™ื“ ืฆื• OAuth ืื•ืŸ OpenID Connect
"ืื•ืžื’ืœื™ืงืœืขืš ื•ื•ืึธืจื˜ ืคื•ืŸ ื“ืขื ื˜ืึธื’: ื’ืขื”ืขืจื˜ ื•ื•ืขื’ืŸ ื“ืขื ื‘ืึธื›ืขืจ ื•ื•ืืก ืคืึทืจืคืึทืœืŸ ื“ื™ ืœื™ื ืงืก ื”ืขืœืคื˜ ืคื•ืŸ ื–ื™ื™ืŸ ื’ื•ืฃ? ืื™ืฆื˜ ืขืจ ืื™ื– ืฉื˜ืขื ื“ื™ืง ืจืขื›ื˜! โ€ (ื“ืขืจื ืึทื›ื˜ืข ืื™ื‘ืขืจื–ืขืฆื•ื ื’, ื•ื•ื™ื™ึทืœ ื“ืขืจ ืึธืจื™ื’ื™ื ืขืœ ื”ืื˜ ื–ื™ื™ืŸ ืื™ื™ื’ืŸ ื•ื•ืึธืจื˜ - ืึทืคึผืคึผืจืึธืงืกื™ ืื™ื‘ืขืจื–ืขืฆื•ื ื’.)

ืขืก ืื™ื– ืงืœืึธืจ ืึทื– ืฉืจื™ื™ื‘ืŸ ืฆื• ื™ืขื“ืขืจ ืžืขื ื˜ืฉ ืคื•ืŸ ื“ื™ ืงืึธื ื˜ืึทืงื˜ ืจืฉื™ืžื” ืื™ื– ื ื™ืฉื˜ ืึทืŸ ืึธืคึผืฆื™ืข. ืื•ืŸ ืื•ื™ื‘ ืื™ืจ ื–ืขื ื˜ ืืคื™ืœื• ืึท ื‘ื™ืกืœ ื•ื•ื™ ืžื™ืจ, ืื™ืจ ื•ื•ืขื˜ ื’ื™ื™ืŸ ืฆื• ืงื™ื™ืŸ ืœืขื ื’ ืฆื• ื•ื™ืกืžื™ื™ื“ืŸ ื•ืžื ื™ื™ื˜ื™ืง ืึทืจื‘ืขื˜. ืฆื•ืž ื’ืœื™ืง, ืฉืจืขืงืœืขืš ืคึผืึธืŸ ืคื•ืŸ ื“ืขื ื˜ืึธื’ ืงืขื ืขืŸ ืคืึทืจื‘ืขื˜ืŸ ืึทืœืข ื“ื™ื™ืŸ ืคืจืขื ื“ื– ืึทืœื™ื™ืŸ! ืฆื• ื˜ืึธืŸ ื“ืึธืก, ืื™ืจ ื ืึธืจ ื“ืึทืจืคึฟืŸ ืฆื• ืขืคึฟืขื ืขืŸ ืึทืงืกืขืก ืฆื• ื“ื™ E- ื‘ืจื™ื•ื• ืคื•ืŸ ื“ื™ื™ืŸ ืงืึธื ื˜ืึทืงื˜ืŸ - ื“ื™ ืคึผืœืึทืฅ ื–ื™ืš ื•ื•ืขื˜ ืฉื™ืงืŸ ื–ื™ื™ ื™ื ื•ื•ื™ื˜ื™ื™ืฉืึทื ื– (OAuth ื›ึผืœืœื™ื)!

ืึทืŸ ื™ืœืœื•ืกื˜ืจืึทื˜ืขื“ ื’ื™ื™ื“ ืฆื• OAuth ืื•ืŸ OpenID Connect
โ€œืึทืœืขืžืขืŸ ื”ืึธื‘ืŸ ืœื™ื‘ ื•ื•ืขืจื˜ืขืจ! - ืฉื•ื™ืŸ ืœืึธื’ื“ ืื™ืŸ? "ื•ื•ืึธืœื˜ ืื™ืจ ืœืึธื–ืŸ ื“ื™ Terrible Pun of the Day ื•ื•ืขื‘ื–ื™ื™ื˜ืœ ืฆื• ืึทืงืกืขืก ื“ื™ื™ืŸ ืงืึธื ื˜ืึทืงื˜ ืจืฉื™ืžื”? - ืื“ืื ืง! ืคึฟื•ืŸ ืื™ืฆื˜ ืึธืŸ, ืžื™ืจ ื•ื•ืขืœืŸ ืฉื™ืงืŸ ื“ืขืจืžืึธื ื•ื ื’ ื™ืขื“ืขืจ ื˜ืึธื’ ืฆื• ืึทืœืขืžืขืŸ ืื™ืจ ื•ื•ื™ืกืŸ, ื‘ื™ื– ื“ื™ ืกื•ืฃ ืคื•ืŸ ืฆื™ื™ื˜! ืื™ืจ ื–ืขื ื˜ ื“ืขืจ ื‘ืขืกื˜ืขืจ ืคืจื™ื™ึทื ื“!"

  1. ืงืœื™ื™ึทื‘ืŸ ื“ื™ื™ืŸ E- ื‘ืจื™ื•ื• ื“ื™ื ืกื˜.
  2. ืื•ื™ื‘ ื ื™ื™ื˜ื™ืง, ื’ื™ื™ืŸ ืฆื• ื“ื™ ืคึผืึธืกื˜ ืคึผืœืึทืฅ ืื•ืŸ ืงืœืึธืฅ ืื™ืŸ ืฆื• ื“ื™ื™ืŸ ื—ืฉื‘ื•ืŸ.
  3. ื’ืขื‘ืŸ ื˜ืขืจืจืึทื‘ืœืข ืคึผื•ืŸ ืคื•ืŸ ื“ื™ ื˜ืึธื’ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืฆื• ืึทืงืกืขืก ื“ื™ื™ืŸ ืงืึธื ื˜ืึทืงื˜ืŸ.
  4. ืฆื•ืจื™ืงืงื•ืžืขืŸ ืฆื• ื“ื™ ืคึผืœืึทืฅ ืคื•ืŸ ื“ื™ ืฉืจืขืงืœืขืš ื•ื•ืึธืจื˜ ืคื•ืŸ ื“ืขื ื˜ืึธื’.

ืื™ืŸ ืคืึทืœ ืื™ืจ ื˜ื•ื™ืฉืŸ ื“ื™ื™ืŸ ืžื™ื™ื ื•ื ื’, ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– ื ื™ืฆืŸ OAuth ืื•ื™ืš ืฆื•ืฉื˜ืขืœืŸ ืึท ื•ื•ืขื’ ืฆื• ืึธืคึผืจื•ืคืŸ ืึทืงืกืขืก. ืึทืžืึธืœ ืื™ืจ ื‘ืึทืฉืœื™ืกืŸ ืึทื– ืื™ืจ ื ื™ื˜ ืžืขืจ ื•ื•ื™ืœืŸ ืฆื• ื˜ื™ื™ืœืŸ ืงืึธื ื˜ืึทืงื˜ืŸ ืžื™ื˜ Terrible Pun of the Day, ืื™ืจ ืงืขื ื˜ ื’ื™ื™ืŸ ืฆื• ื“ื™ ืคึผืึธืกื˜ ืคึผืœืึทืฅ ืื•ืŸ ื‘ืึทื–ื™ื™ึทื˜ื™ืงืŸ ื“ืขื ื•ื•ืึธืจื˜ ืคื•ืŸ ื“ืขืจ ืจืฉื™ืžื” ืคื•ืŸ ืึธื˜ืขืจื™ื™ื–ื“ ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื–.

OAuth Flow

ืžื™ืจ ื”ืึธื‘ืŸ ื ืึธืจ ื“ื•ืจื›ื’ืขื’ืื ื’ืขืŸ ื•ื•ืึธืก ืื™ื– ื™ื•ื–ืฉืึทื•ื•ืึทืœื™ ื’ืขืจื•ืคืŸ ืœื•ื™ืคืŸ [ืคืœื•ืก] OAuth. ืื™ืŸ ืื•ื ื“ื–ืขืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ื“ืขื ืœื•ื™ืคืŸ ื‘ืืฉื˜ื™ื™ื˜ ืคื•ืŸ ืงืขื ื˜ื™ืง ืกื˜ืขืคึผืก, ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ ืขื˜ืœืขื›ืข ื•ืžื–ืขื™ืง ืกื˜ืขืคึผืก, ืื™ืŸ ื•ื•ืึธืก ืฆื•ื•ื™ื™ ื‘ืึทื“ื™ื ื•ื ื’ืก ืฉื˜ื™ืžืขืŸ ืื•ื™ืฃ ืึท ื–ื™ื›ืขืจ ื•ื•ืขืงืกืœ ืคื•ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข. ื“ื™ ืคืจื™ืขืจื“ื™ืงืข ื‘ื™ื™ืฉืคึผื™ืœ ืคื•ืŸ ืฉืจืขืงืœืขืš ืคึผืึธืŸ ืคื•ืŸ ื“ื™ ื˜ืึธื’ ื ื™ืฆื˜ ื“ื™ ืžืขืจืกื˜ ืคึผืจืึธืกื˜ OAuth 2.0 ืœื•ื™ืคืŸ, ื‘ืืงืื ื˜ ื•ื•ื™ ื“ื™ "ืึธื˜ืขืจื™ื–ืึทื˜ื™ืึธืŸ ืงืึธื“" ืœื•ื™ืคืŸ. ["ืึทื•ื˜ื”ืึธืจื™ื–ืึทื˜ื™ืึธืŸ ืงืึธื“" ืœื•ื™ืคืŸ].

ืื™ื™ื“ืขืจ ื“ื™ื™ื•ื•ื™ื ื’ ืื™ืŸ ื“ื™ ื“ืขื˜ืึทื™ืœืก ืคื•ืŸ ื•ื•ื™ OAuth ืึทืจื‘ืขื˜, ืœืึธื–ืŸ ืื•ื ื“ื– ืจืขื“ืŸ ื•ื•ืขื’ืŸ ื“ื™ ื˜ื™ื™ึทื˜ืฉ ืคื•ืŸ ืขื˜ืœืขื›ืข ื˜ืขืจืžื™ื ืขืŸ:

  • ืžื™ื˜ืœ ื‘ืึทื–ื™ืฆืขืจ:

    ืึทืŸ ื™ืœืœื•ืกื˜ืจืึทื˜ืขื“ ื’ื™ื™ื“ ืฆื• OAuth ืื•ืŸ OpenID Connect

    ืขืก ืื™ื– ืื™ืจ! ืื™ืจ ืคืึทืจืžืึธื’ืŸ ื“ื™ื™ืŸ ืงืจืึทื“ืขื ื˜ืฉืึทืœื–, ื“ื™ื™ืŸ ื“ืึทื˜ืŸ ืื•ืŸ ืงืึธื ื˜ืจืึธืœื™ืจืŸ ืึทืœืข ืึทืงื˜ื™ื•ื•ื™ื˜ืขื˜ืŸ ื•ื•ืึธืก ืงืขืŸ ื–ื™ื™ืŸ ื’ืขื˜ืืŸ ืื•ื™ืฃ ื“ื™ื™ืŸ ืึทืงืึทื•ื ืฅ.

  • ืงื•ื™ื ืข:

    ืึทืŸ ื™ืœืœื•ืกื˜ืจืึทื˜ืขื“ ื’ื™ื™ื“ ืฆื• OAuth ืื•ืŸ OpenID Connect

    ืึท ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ (ืœืžืฉืœ, ื“ื™ Terrible Pun of the Day ื“ื™ื ืกื˜) ื•ื•ืึธืก ื•ื•ื™ืœ ืฆื• ืึทืงืกืขืก ืึธื“ืขืจ ื“ื•ืจื›ืคื™ืจืŸ ื–ื™ื›ืขืจ ืึทืงืฉืึทื ื– ืื™ืŸ ื‘ื™ื›ืึทืฃ ืคื•ืŸ ืžื™ื˜ืœ ื‘ืึทื–ื™ืฆืขืจ'ืึท.

  • ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืกืขืจื•ื•ื™ืจืขืจ:

    ืึทืŸ ื™ืœืœื•ืกื˜ืจืึทื˜ืขื“ ื’ื™ื™ื“ ืฆื• OAuth ืื•ืŸ OpenID Connect

    ื“ื™ ืึทืคึผ ื•ื•ืึธืก ื•ื•ื™ื™ืกื˜ ืžื™ื˜ืœ ื‘ืึทื–ื™ืฆืขืจ'ืึท ืื•ืŸ ืื™ืŸ ื•ื•ืึธืก ื™ื• ืžื™ื˜ืœ ื‘ืึทื–ื™ืฆืขืจ'ืึท ืฉื•ื™ืŸ ื”ืึธื‘ืŸ ืึท ื—ืฉื‘ื•ืŸ.

  • ืžื™ื˜ืœ ืกืขืจื•ื•ืขืจ:

    ืึทืŸ ื™ืœืœื•ืกื˜ืจืึทื˜ืขื“ ื’ื™ื™ื“ ืฆื• OAuth ืื•ืŸ OpenID Connect

    ืึทืคึผืคึผืœื™ืงืึทื˜ื™ืึธืŸ ืคึผืจืึธื’ืจืึทืžืžื™ื ื’ ืฆื•ื‘ื™ื ื“ (ืึทืคึผื™) ืึธื“ืขืจ ื“ื™ื ืขืŸ ืึทื– ืงื•ื™ื ืข ื•ื•ื™ืœ ืฆื• ื ื•ืฆืŸ ืื•ื™ืฃ ื‘ื™ื›ืึทืฃ ืžื™ื˜ืœ ื‘ืึทื–ื™ืฆืขืจ'ืึท.

  • ืจื™ื“ื™ืจืขืงื˜ URI:

    ืึทืŸ ื™ืœืœื•ืกื˜ืจืึทื˜ืขื“ ื’ื™ื™ื“ ืฆื• OAuth ืื•ืŸ OpenID Connect

    ื“ืขืจ ืœื™ื ืง ืึทื– ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืกืขืจื•ื•ื™ืจืขืจ ื•ื•ืขื˜ ืจื™ื“ืขืจืขืงื˜ ืžื™ื˜ืœ ื‘ืึทื–ื™ืฆืขืจ'ืื•ืŸ ื ืึธืš ื’ืขื‘ืŸ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืงื•ื™ื ืข'ื‘ื™ื™ึท. ืขืก ืื™ื– ืžืืœ ืจื™ืคืขืจื“ ืฆื• ื•ื•ื™ ื“ื™ "ืงืึธืœื‘ืึทืง URL".

  • ืขื ื˜ืคืขืจ ื˜ื™ืคึผ:

    ืึทืŸ ื™ืœืœื•ืกื˜ืจืึทื˜ืขื“ ื’ื™ื™ื“ ืฆื• OAuth ืื•ืŸ OpenID Connect

    ื“ืขืจ ื˜ื™ืคึผ ืคื•ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื“ืขืจื•ื•ืึทืจื˜ ืฆื• ื–ื™ื™ืŸ ื‘ืืงื•ืžืขืŸ ืงื•ื™ื ืข. ื“ื™ ืžืขืจืกื˜ ืคึผืจืึธืกื˜ ืขื ื˜ืคืขืจ ื˜ื™ืคึผ'ืึธื”ื ืื™ื– ื“ื™ ืงืึธื“, ื•ื•ืึธืก ืื™ื– ืงื•ื™ื ืข ืขืจื•ื•ืืจื˜ืขื˜ ืฆื• ื‘ืืงื•ืžืขืŸ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืงืึธื•ื“.

  • ืคืึทืจื ืขื:

    ืึทืŸ ื™ืœืœื•ืกื˜ืจืึทื˜ืขื“ ื’ื™ื™ื“ ืฆื• OAuth ืื•ืŸ OpenID Connect

    ื“ืึธืก ืื™ื– ืึท ื“ื™ื˜ื™ื™ืœื“ ื‘ืึทืฉืจื™ื™ึทื‘ื•ื ื’ ืคื•ืŸ ื“ื™ ืคึผืขืจืžื™ืฉืึทื ื– ื•ื•ืึธืก ื–ืขื ืขืŸ ืคืืจืœืื ื’ื˜ ืงื•ื™ื ืข'ื™, ืึทื–ืึท ื•ื•ื™ ืึทืงืกืขืกื™ื ื’ ื“ืึทื˜ืŸ ืึธื“ืขืจ ื“ื•ืจื›ืคื™ืจืŸ ื–ื™ื›ืขืจ ืึทืงืฉืึทื ื–.

  • ืฆื•ืฉื˜ื™ืžืขืŸ:

    ืึทืŸ ื™ืœืœื•ืกื˜ืจืึทื˜ืขื“ ื’ื™ื™ื“ ืฆื• OAuth ืื•ืŸ OpenID Connect

    ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืกืขืจื•ื•ื™ืจืขืจ ื ืขืžื˜ ืกืงืึธืคึผืขืกื’ืขื‘ืขื˜ืŸ ืงื•ื™ื ืข'ืึธื, ืื•ืŸ ืคืจืขื’ื˜ ืžื™ื˜ืœ ื‘ืึทื–ื™ืฆืขืจ'ืึท, ืื™ื– ืขืจ ื’ืจื™ื™ื˜ ืฆื• ืฆื•ืฉื˜ืขืœืŸ ืงื•ื™ื ืข'ื”ืึธื‘ืŸ ื“ื™ ืฆื•ื ืขืžืขืŸ ืคึผืขืจืžื™ืฉืึทื ื–.

  • ืงืœื™ืขื ื˜ ืฉื™ื™ึทืŸ:

    ืึทืŸ ื™ืœืœื•ืกื˜ืจืึทื˜ืขื“ ื’ื™ื™ื“ ืฆื• OAuth ืื•ืŸ OpenID Connect

    ื“ืขื ID ืื™ื– ื’ืขื ื™ืฆื˜ ืฆื• ื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ ืงื•ื™ื ืข' ืื•ื™ืฃ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืกืขืจื•ื•ื™ืจืขืจ'ืข.

  • ืงืœื™ืขื ื˜ ืกื•ื“:

    ืึทืŸ ื™ืœืœื•ืกื˜ืจืึทื˜ืขื“ ื’ื™ื™ื“ ืฆื• OAuth ืื•ืŸ OpenID Connect

    ื“ืึธืก ืื™ื– ื“ื™ ืคึผืึทืจืึธืœ ื•ื•ืึธืก ืื™ื– ื‘ืœื•ื™ื– ื‘ืืงืื ื˜ ืงื•ื™ื ืข'ื• ืื•ืŸ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืกืขืจื•ื•ื™ืจืขืจ'ื‘ื™ื™ึท. ืขืก ืึทืœืึทื•ื– ื–ื™ื™ ืฆื• ื˜ื™ื™ืœืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื‘ื™ื›ื™ื“ืขืก.

  • ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืงืึธื•ื“:

    ืึทืŸ ื™ืœืœื•ืกื˜ืจืึทื˜ืขื“ ื’ื™ื™ื“ ืฆื• OAuth ืื•ืŸ OpenID Connect

    ืฆื™ื™ึทื˜ื•ื•ื™ื™ึทืœื™ืง ืงืึธื“ ืžื™ื˜ ืึท ืงื•ืจืฅ ืฆื™ื™ึทื˜ ืคื•ืŸ ื’ื™ืœื˜ื™ืงื™ื™ึทื˜, ื•ื•ืึธืก ืงื•ื™ื ืข ื’ื™ื˜ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืกืขืจื•ื•ื™ืจืขืจ'ื™ ืื™ืŸ ื•ื•ืขืงืกืœ ืคึฟืึทืจ ืึทืงืกืขืก ื˜ืึธืงืขืŸ.

  • ืึทืงืกืขืก ื˜ืึธืงืขืŸ:

    ืึทืŸ ื™ืœืœื•ืกื˜ืจืึทื˜ืขื“ ื’ื™ื™ื“ ืฆื• OAuth ืื•ืŸ OpenID Connect

    ื“ืขืจ ืฉืœื™ืกืœ ื•ื•ืึธืก ื“ืขืจ ืงืœื™ืขื ื˜ ื•ื•ืขื˜ ื ื•ืฆืŸ ืฆื• ื™ื‘ืขืจื’ืขื‘ืŸ ืžื™ื˜ ืžื™ื˜ืœ ืกืขืจื•ื•ืขืจ'ืึธื. ื ืกืึธืจื˜ ืคื•ืŸ ืึธืคึผืฆื™ื™ื›ืŸ ืึธื“ืขืจ ืฉืœื™ืกืœ ืงืึธืจื˜ ื•ื•ืึธืก ื’ื™ื˜ ืงื•ื™ื ืข'ื”ืึธื‘ืŸ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืฆื• ื‘ืขื˜ืŸ ื“ืึทื˜ืŸ ืึธื“ืขืจ ื“ื•ืจื›ืคื™ืจืŸ ืึทืงืฉืึทื ื– ืื•ื™ืฃ ืžื™ื˜ืœ ืกืขืจื•ื•ืขืจ'ืข ืื•ื™ืฃ ื“ื™ื™ืŸ ื‘ื™ื›ืึทืฃ.

ื˜ืึธืŸ: ืžืืœ ืึทื•ื˜ื”ืึธืจื™ื–ืึทื˜ื™ืึธืŸ ืกืขืจื•ื•ื™ืจืขืจ ืื•ืŸ ืžื™ื˜ืœ ืกืขืจื•ื•ื™ืจืขืจ ื–ืขื ืขืŸ ื“ื™ ื–ืขืœื‘ืข ืกืขืจื•ื•ืขืจ. ืึธื‘ืขืจ, ืื™ืŸ ืขื˜ืœืขื›ืข ืงืึทืกืขืก, ื“ืึธืก ืงืขืŸ ื–ื™ื™ืŸ ืคืึทืจืฉื™ื“ืขื ืข ืกืขืจื•ื•ืขืจืก, ืืคื™ืœื• ืื•ื™ื‘ ื–ื™ื™ ื’ืขื”ืขืจืŸ ื ื™ืฉื˜ ืฆื• ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืึธืจื’ืึทื ื™ื–ืึทืฆื™ืข. ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ื“ืขืจ ืึทื•ื˜ื”ืึธืจื™ื–ืึทื˜ื™ืึธืŸ ืกืขืจื•ื•ื™ืจืขืจ ืงืขืŸ ื–ื™ื™ืŸ ืึท ื“ืจื™ื˜ ืคึผืึทืจื˜ื™ื™ ืกืขืจื•ื•ื™ืก ื˜ืจืึทืกื˜ื™ื“ ื“ื•ืจืš ื“ื™ ืžื™ื˜ืœ ืกืขืจื•ื•ื™ืจืขืจ.

ืื™ืฆื˜ ืึทื– ืžื™ืจ ื”ืึธื‘ืŸ ื‘ืื“ืขืงื˜ ื“ื™ ื”ืึทืจืฅ ืงืึทื ืกืขืคึผืก ืคื•ืŸ OAuth 2.0, ืœืึธื–ืŸ ืื•ื ื“ื– ื’ื™ื™ืŸ ืฆื•ืจื™ืง ืฆื• ืื•ื ื“ื–ืขืจ ื‘ื™ื™ืฉืคึผื™ืœ ืื•ืŸ ื ืขืžืขืŸ ืึท ื ืขืขื ื˜ืขืจ ืงื•ืง ืื™ืŸ ื•ื•ืึธืก ื›ืึทืคึผืึทื ื– ืื™ืŸ ื“ื™ OAuth ืœื•ื™ืคืŸ.

ืึทืŸ ื™ืœืœื•ืกื˜ืจืึทื˜ืขื“ ื’ื™ื™ื“ ืฆื• OAuth ืื•ืŸ OpenID Connect

  1. ืื™ืจ, ืžื™ื˜ืœ ื‘ืึทื–ื™ืฆืขืจ, ืื™ืจ ื•ื•ื™ืœืŸ ืฆื• ืฆื•ืฉื˜ืขืœืŸ ื“ื™ Terrible Pun of the Day ื“ื™ื ืกื˜ (ืงื•ื™ื ืขื™) ืึทืงืกืขืก ืฆื• ื“ื™ื™ืŸ ืงืึธื ื˜ืึทืงื˜ืŸ ืึทื–ื•ื™ ืึทื– ื–ื™ื™ ืงืขื ืขืŸ ืฉื™ืงืŸ ื™ื ื•ื•ื™ื˜ื™ื™ืฉืึทื ื– ืฆื• ืึทืœืข ื“ื™ื™ืŸ ืคืจืขื ื“ื–.
  2. ืงื•ื™ื ืข ืจื™ื“ืขืจืขืงืฅ ื“ืขื ื‘ืœืขื˜ืขืจืขืจ ืฆื• ื“ื™ ื‘ืœืึทื˜ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืกืขืจื•ื•ื™ืจืขืจ'ืึท ืื•ืŸ ืึทืจื™ื™ึทื ื ืขืžืขืŸ ืื™ืŸ ืึธื ืคึฟืจืขื’ ืงืœื™ืขื ื˜ ืฉื™ื™ึทืŸ, ืจื™ื“ื™ืจืขืงื˜ URI, ืขื ื˜ืคืขืจ ื˜ื™ืคึผ ืื•ืŸ ืื™ื™ื ืขืจ ืึธื“ืขืจ ืžืขืจ ืกืงืึธืคึผืขืก (ืคึผืขืจืžื™ืฉืึทื ื–) ืขืก ื“ืึทืจืฃ.
  3. ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืกืขืจื•ื•ื™ืจืขืจ ื•ื•ืขืจืึทืคื™ื™ื– ืื™ืจ, ืึทืกืงื™ื ื’ ืคึฟืึทืจ ืึท ื ืืžืขืŸ ืื•ืŸ ืคึผืึทืจืึธืœ ืื•ื™ื‘ ื ื™ื™ื˜ื™ืง.
  4. ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืกืขืจื•ื•ื™ืจืขืจ ื“ื™ืกืคึผืœื™ื™ื– ืึท ืคืึธืจืขื ืฆื•ืฉื˜ื™ืžืขืŸ (ืงืึธื ืคืขืจืžื™ื™ืฉืึทื ื–) ืžื™ื˜ ืึท ืจืฉื™ืžื” ืคื•ืŸ ืึทืœืข ืกืงืึธืคึผืขืกื’ืขื‘ืขื˜ืŸ ืงื•ื™ื ืข'ืึธื. ืื™ืจ ืฉื˜ื™ืžืขืŸ ืึธื“ืขืจ ืึธืคึผื–ืึธื’ืŸ.
  5. ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืกืขืจื•ื•ื™ืจืขืจ ืจื™ื“ืขืจืขืงืฅ ืื™ืจ ืฆื• ื“ืขื ืคึผืœืึทืฅ ืงื•ื™ื ืข'ืึท, ื ื™ืฆืŸ ืจื™ื“ื™ืจืขืงื˜ URI ืฆื•ื–ืึทืžืขืŸ ืžื™ื˜ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืงืึธื•ื“ (ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืงืึธื“).
  6. ืงื•ื™ื ืข ืงืึทืžื™ื•ื ืึทืงื™ื™ืฅ ื’ืœื™ื™ึทืš ืžื™ื˜ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืกืขืจื•ื•ื™ืจืขืจ'ืึธื”ื (ื‘ื™ื™ืคึผืึทืกื™ื ื’ ื“ืขื ื‘ืœืขื˜ืขืจืขืจ ืžื™ื˜ืœ ื‘ืึทื–ื™ืฆืขืจ'ืึท) ืื•ืŸ ื‘ืขืฉืึธืœืขื ืกืขื ื“ื– ืงืœื™ืขื ื˜ ืฉื™ื™ึทืŸ, ืงืœื™ืขื ื˜ ืกื•ื“ ะธ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืงืึธื•ื“.
  7. ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืกืขืจื•ื•ื™ืจืขืจ ื˜ืฉืขืง ื“ื™ ื“ืึทื˜ืŸ ืื•ืŸ ืจื™ืกืคึผืึทื ื“ื– ืžื™ื˜ ืึทืงืกืขืก ื˜ืึธืงืขืŸ'ืึธื (ืึทืงืกืขืก ืกื™ืžืขืŸ).
  8. ืื™ืฆื˜ ืงื•ื™ื ืข ืงืขื ืขืŸ ื ื•ืฆืŸ ืึทืงืกืขืก ื˜ืึธืงืขืŸ ืฆื• ืฉื™ืงืŸ ืึท ื‘ืงืฉื” ืฆื• ืžื™ื˜ืœ ืกืขืจื•ื•ืขืจ ืฆื• ื‘ืึทืงื•ืžืขืŸ ืึท ืจืฉื™ืžื” ืคื•ืŸ ืงืึธื ื˜ืึทืงื˜ืŸ.

ืงืœื™ืขื ื˜ ืฉื™ื™ึทืŸ ืื•ืŸ ืกื•ื“

ืœืึทื ื’ ืื™ื™ื“ืขืจ ืื™ืจ ืขืจืœื•ื™ื‘ื˜ ืฉืจืขืงืœืขืš ืคึผืึธืŸ ืคื•ืŸ ื“ื™ ื˜ืึธื’ ืฆื• ืึทืงืกืขืก ื“ื™ื™ืŸ ืงืึธื ื˜ืึทืงื˜ืŸ, ื“ืขืจ ืงืœื™ืขื ื˜ ืื•ืŸ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืกืขืจื•ื•ื™ืจืขืจ ื”ืื˜ ื’ืขื’ืจื™ื ื“ืขื˜ ืึท ืืจื‘ืขื˜ืŸ ืฉื™ื™ื›ื•ืช. ื“ืขืจ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืกืขืจื•ื•ื™ืจืขืจ ื“ื–ืฉืขื ืขืจื™ื™ื˜ืึทื“ ื“ื™ ืงืœื™ืขื ื˜ ืฉื™ื™ึทืŸ ืื•ืŸ ืงืœื™ืขื ื˜ ืกื•ื“ (ืžืืœ ื’ืขืจื•ืคืŸ App ID ะธ ืึทืคึผ ืกื•ื“) ืื•ืŸ ื’ืขืฉื™ืงื˜ ื–ื™ื™ ืฆื• ื“ืขื ืงืœื™ืขื ื˜ ืคึฟืึทืจ ื•ื•ื™ื™ึทื˜ืขืจ ื™ื ื˜ืขืจืึทืงืฉืึทืŸ ืื™ืŸ OAuth.

ืึทืŸ ื™ืœืœื•ืกื˜ืจืึทื˜ืขื“ ื’ื™ื™ื“ ืฆื• OAuth ืื•ืŸ OpenID Connect
"- ื”ืขืœื! ืื™ืš ื•ื•ืึธืœื˜ ื•ื•ื™ ืฆื• ืึทืจื‘ืขื˜ืŸ ืžื™ื˜ ืื™ืจ! - ื–ื™ื›ืขืจ, ื ื™ืฉื˜ ืึท ืคึผืจืึธื‘ืœืขื! ื“ืึธ ื–ืขื ืขืŸ ื“ื™ื™ืŸ ืงืœื™ืขื ื˜ ืฉื™ื™ึทืŸ ืื•ืŸ ืกื•ื“!

ื“ืขืจ ื ืึธืžืขืŸ ื™ืžืคึผืœื™ื™ื– ืึทื– ื“ืขืจ ืงืœื™ืขื ื˜ ืกื•ื“ ืžื•ื–ืŸ ื–ื™ื™ืŸ ื’ืขื”ืืœื˜ืŸ ืกื•ื“ ืึทื–ื•ื™ ืึทื– ื‘ืœื•ื™ื– ื“ืขืจ ืงืœื™ืขื ื˜ ืื•ืŸ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืกืขืจื•ื•ื™ืจืขืจ ื•ื•ื™ืกืŸ ืขืก. ื ืึธืš ืึทืœืข, ืขืก ืื™ื– ืžื™ื˜ ื–ื™ื™ืŸ ื”ื™ืœืฃ ืึทื– ื“ืขืจ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืกืขืจื•ื•ื™ืจืขืจ ืงืึทื ืคืขืจืžื– ื“ื™ ืืžืช ืคื•ืŸ ื“ืขื ืงืœื™ืขื ื˜.

ืื‘ืขืจ ืึทื– ืก ื ื™ื˜ ืึทืœืข ... ื‘ื™ื˜ืข ื‘ืึทื’ืจื™ืกืŸ OpenID Connect!

OAuth 2.0 ืื™ื– ื‘ืœื•ื™ื– ื“ื™ื–ื™ื™ื ื“ ืคึฟืึทืจ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ - ืฆื• ืฆื•ืฉื˜ืขืœืŸ ืึทืงืกืขืก ืฆื• ื“ืึทื˜ืŸ ืื•ืŸ ืคืึทื ื’ืงืฉืึทื ื– ืคื•ืŸ ืื™ื™ืŸ ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ืฆื• ืื ื“ืขืจืŸ. ืึธืคึผืขื ื™ื“ ืงืึธื ื ืขืงื˜ (OIDC) ืื™ื– ืึท ื“ื™ืŸ ืฉื™ื›ื˜ืข ืื•ื™ืฃ ืฉืคึผื™ืฅ ืคื•ืŸ OAuth 2.0 ื•ื•ืึธืก ืžื•ืกื™ืฃ ื“ื™ ืœืึธื’ื™ืŸ ืื•ืŸ ืคึผืจืึธืคื™ืœ ื“ืขื˜ืึทื™ืœืก ืคื•ืŸ ื“ื™ ื‘ืึทื ื™ืฆืขืจ ื•ื•ืึธืก ืื™ื– ืœืึธื’ื“ ืื™ืŸ ื“ืขื ื—ืฉื‘ื•ืŸ. ื“ืขืจ ืึธืจื’ืึทื ื™ื–ืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹ืึท ืœืึธื’ื™ืŸ ืกืขืกื™ืข ืื™ื– ืึธืคื˜ ืจื™ืคืขืจื“ ืฆื• ื•ื•ื™ ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ [ืึธื˜ืขื ื˜ืึทืงื™ื™ืฉืึทืŸ], ืื•ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ืขื ื‘ืึทื ื™ืฆืขืจ ืœืึธื’ื“ ืื™ืŸ ื“ื™ ืกื™ืกื˜ืขื (ื“"ื” ื•ื•ืขื’ืŸ ืžื™ื˜ืœ ื‘ืึทื–ื™ืฆืขืจืข), โ€” ืคึผืขืจื–ืขื ืœืขืš ื“ืึทื˜ืŸ [ืื™ื“ืขื ื˜ื™ื˜ืขื˜]. ืื•ื™ื‘ ื“ืขืจ ืื•ื™ื˜ืึธืจื™ื–ืึทื˜ื™ืึธืŸ ืกืขืจื•ื•ื™ืจืขืจ ืฉื˜ื™ืฆื˜ OIDC, ืขืก ืื™ื– ืžืืœ ืจื™ืคืขืจื“ ืฆื• ื•ื•ื™ ืฉืคึผื™ื™ึทื–ืขืจ ืคื•ืŸ ืคึผืขืจื–ืขื ืœืขืš ื“ืึทื˜ืŸ [ืื™ื“ืขื ื˜ื™ื˜ืขื˜ ืฉืคึผื™ื™ึทื–ืขืจ]ื•ื•ื™ื™ึทืœ ืขืก ื’ื™ื˜ ืงื•ื™ื ืข'ื”ืึธื‘ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ืžื™ื˜ืœ ื‘ืึทื–ื™ืฆืขืจ'ืข.

OpenID Connect ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื™ื ืกื˜ืจื•ืžืขื ื˜ ืกื™ื ืขืจื™ืึธื•ื– ื•ื•ื• ืึท ืื™ื™ืŸ ืœืึธื’ื™ืŸ ืงืขื ืขืŸ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืื™ืŸ ืงื™ื™ืคืœ ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– - ื“ืขืจ ืฆื•ื’ืึทื ื’ ืื™ื– ืื•ื™ืš ื‘ืืงืื ื˜ ื•ื•ื™ ืื™ื™ืŸ ืฆื™ื™ื›ืŸ ืื•ื™ืฃ (SSO). ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ืึท ืึทืคึผืœืึทืงื™ื™ืฉืึทืŸ ืงืขืŸ ืฉื˜ื™ืฆืŸ SSO ื™ื ืึทื’ืจื™ื™ืฉืึทืŸ ืžื™ื˜ ื’ืขื–ืขืœืฉืึทืคื˜ืœืขืš ื ืขื˜ื•ื•ืึธืจืงืก ืึทื–ืึท ื•ื•ื™ ืคืึทืกืขื‘ืึธืึธืง ืึธื“ืขืจ ื˜ื•ื•ื™ื˜ื˜ืขืจ, ืึทืœืึทื•ื™ื ื’ ื™ื•ื–ืขืจื– ืฆื• ื ื•ืฆืŸ ืึท ื—ืฉื‘ื•ืŸ ื•ื•ืึธืก ื–ื™ื™ ื”ืึธื‘ืŸ ืฉื•ื™ืŸ ืื•ืŸ ื‘ืขืกืขืจ ืฆื• ื ื•ืฆืŸ.

ืึทืŸ ื™ืœืœื•ืกื˜ืจืึทื˜ืขื“ ื’ื™ื™ื“ ืฆื• OAuth ืื•ืŸ OpenID Connect

ื“ื™ ืœื•ื™ืคืŸ (ืœื•ื™ืคืŸ) OpenID Connect ืงื•ืงื˜ ื“ื™ ื–ืขืœื‘ืข ื•ื•ื™ ืื™ืŸ ื“ื™ ืคืึทืœ ืคื•ืŸ OAuth. ื“ืขืจ ื‘ืœื•ื™ื– ื—ื™ืœื•ืง ืื™ื– ืึทื– ืื™ืŸ ื“ื™ ืขืจืฉื˜ื™ืง ื‘ืขื˜ืŸ, ื“ื™ ืกืคึผืขืฆื™ืคื™ืฉ ืคืึทืจื ืขื ื’ืขื ื™ืฆื˜ ืื™ื– openid, โ€” ื ืงื•ื™ื ืข ื™ื•ื•ืขื ื˜ืฉืึทื•ื•ืึทืœื™ ื’ืขืฅ ื•ื•ื™ ืึทืงืกืขืก ื˜ืึธืงืขืŸืื•ืŸ ID ื˜ืึธืงืขืŸ.

ืึทืŸ ื™ืœืœื•ืกื˜ืจืึทื˜ืขื“ ื’ื™ื™ื“ ืฆื• OAuth ืื•ืŸ OpenID Connect

ืคึผื•ื ืงื˜ ื•ื•ื™ ืื™ืŸ ื“ื™ OAuth ืœื•ื™ืคืŸ, ืึทืงืกืขืก ื˜ืึธืงืขืŸ ืื™ืŸ OpenID Connect, ื“ืึธืก ืื™ื– ืึท ื•ื•ืขืจื˜ ื•ื•ืึธืก ืื™ื– ื ื™ืฉื˜ ืงืœืึธืจ ืงื•ื™ื ืข'ื‘ื™ื™ึท. ืคื•ืŸ ืฉื˜ืื ื“ืคื•ื ืงื˜ ืงื•ื™ื ืข'ืึท ืึทืงืกืขืก ื˜ืึธืงืขืŸ ืจืขืคึผืจืึทื–ืขื ืฅ ืึท ืฉื˜ืจื™ืงืœ ืคื•ืŸ ืื•ืชื™ื•ืช ื•ื•ืึธืก ืื™ื– ื“ื•ืจื›ื’ืขื’ืื ื’ืขืŸ ืฆื•ื–ืืžืขืŸ ืžื™ื˜ ื™ืขื“ืขืจ ื‘ืงืฉื” ืฆื• ืžื™ื˜ืœ ืกืขืจื•ื•ืขืจ'ื™, ื•ื•ืึธืก ื“ื™ื˜ืขืจืžืึทื ื– ืื•ื™ื‘ ื“ื™ ืกื™ืžืขืŸ ืื™ื– ื’ื™ืœื˜ื™ืง. ID ื˜ืึธืงืขืŸ ืจืขืคึผืจืึทื–ืขื ืฅ ืึท ื’ืึธืจ ืึทื ื“ืขืจืฉ ื–ืึทืš.

ID ื˜ืึธืงืขืŸ ืื™ื– ืึท JWT

ID ื˜ืึธืงืขืŸ ืื™ื– ืึท ืกืคึผืขืฉืœื™ ืคืึธืจืžืึทื˜ื˜ืขื“ ืฉื˜ืจื™ืงืœ ืคื•ืŸ ืื•ืชื™ื•ืช ื‘ืืงืื ื˜ ื•ื•ื™ JSON ื•ื•ืขื‘ ื˜ืึธืงืขืŸ ืึธื“ืขืจ JWT (ืžืืœ JWT ื˜ืึธืงืขื ืก ื–ืขื ืขืŸ ืคึผืจืึทื ืึทื•ื ืกื˜ ื•ื•ื™ "ื“ื–ืฉืึทืฅ"). ืคึฟืึทืจ ืึทืจื•ื™ืก ืึทื‘ื–ืขืจื•ื•ืขืจื–, JWT ืงืขืŸ ื•ื™ืกืงื•ืžืขืŸ ื•ื•ื™ ื™ื ื’ืงืึทืžืคึผืจืึทื›ืขื ืกื™ื‘ืึทืœ ื’ื™ื‘ืจื™ืฉ, ืึธื‘ืขืจ ืงื•ื™ื ืข ืงืขื ืขืŸ ืขืงืกื˜ืจืึทืงื˜ ืคืึทืจืฉื™ื“ืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ืคื•ืŸ โ€‹โ€‹ื“ื™ JWT, ืึทื–ืึท ื•ื•ื™ ืฉื™ื™ึทืŸ, ื ืืžืขืŸ, ืœืึธื’ื™ืŸ ืฆื™ื™ื˜, ืขืงืกืคึผืขืจื™ื™ืฉืึทืŸ ื˜ืึธื’ ID ื˜ืึธืงืขืŸ'ืึท, ื“ื™ ื‘ื™ื™ึทื–ื™ื™ึทืŸ ืคื•ืŸ ืคืจื•ื•ื•ืŸ ืฆื• ืึทืจื™ื™ึทื ืžื™ืฉื  ื–ื™ืš ืžื™ื˜ ื“ื™ JWT. ื“ืึทื˜ืŸ ื™ืŸ ID ื˜ืึธืงืขืŸ'ืึท ื–ืขื ืขืŸ ื’ืขืจื•ืคืŸ ืึทืคึผืœืึทืงื™ื™ืฉืึทื ื– [ื˜ืขื ื”ื˜].

ืึทืŸ ื™ืœืœื•ืกื˜ืจืึทื˜ืขื“ ื’ื™ื™ื“ ืฆื• OAuth ืื•ืŸ OpenID Connect

ืื™ืŸ ื“ืขื ืคืึทืœ ืคื•ืŸ OIDC, ืขืก ืื™ื– ืื•ื™ืš ืึท ื ืึธืจืžืึทืœ ื•ื•ืขื’ ื“ื•ืจืš ื•ื•ืึธืก ืงื•ื™ื ืข ืงืขืŸ ื‘ืขื˜ืŸ ื ืึธืš ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ืขื ื™ื—ื™ื“ [ืื™ื“ืขื ื˜ื™ื˜ืขื˜] ืคื•ืŸ ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ ืกืขืจื•ื•ื™ืจืขืจ'ืึท, ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ืึท ื‘ืœื™ืฆืคึผืึธืกื˜ ืึทื“ืจืขืก ื ื™ืฆืŸ ืึทืงืกืขืก ื˜ืึธืงืขืŸ.

ืœืขืจื ืขืŸ ืžืขืจ ื•ื•ืขื’ืŸ OAuth ืื•ืŸ OIDC

ืึทื–ื•ื™, ืžื™ืจ ื‘ืขืงื™ืฆืขืจ ืจื™ื•ื•ื™ื•ื“ ื•ื•ื™ OAuth ืื•ืŸ OIDC ืึทืจื‘ืขื˜. ื’ืจื™ื™ื˜ ืฆื• ื’ืจืึธื‘ืŸ ื“ื™ืคึผืขืจ? ื“ืึธ ื–ืขื ืขืŸ ื ืึธืš ืจืขืกื•ืจืกืŸ ืฆื• ื”ืขืœืคึฟืŸ ืื™ืจ ืœืขืจื ืขืŸ ืžืขืจ ื•ื•ืขื’ืŸ OAuth 2.0 ืื•ืŸ OpenID Connect:

ื•ื•ื™ ืฉื˜ืขื ื“ื™ืง, ืคื™ืœืŸ ืคืจื™ื™ ืฆื• ื‘ืึทืžืขืจืงืŸ. ืฆื• ื”ืึทืœื˜ืŸ ืึทืจื•ื™ืฃ-ืฆื•-ื˜ืึธื’ ืžื™ื˜ ืื•ื ื“ื–ืขืจ ืœืขืฆื˜ืข ื ื™ื™ึทืขืก, ืึทื‘ืึธื ื™ืจืŸ ืฆื• ื˜ื•ื•ื™ื˜ื˜ืขืจ ะธ ื™ืึธื•ื˜ื•ื‘ืข ื’ื•ื˜ ืคึฟืึทืจ ื“ืขื•ื•ืขืœืึธืคึผืขืจืก!

ืคึผืก ืคื•ืŸ ืื™ื‘ืขืจื–ืขืฆืขืจ

ืœื™ื™ืขื ืขืŸ ืื•ื™ืš ืื•ื™ืฃ ืื•ื ื“ื–ืขืจ ื‘ืœืึธื’:

ืžืงื•ืจ: www.habr.com

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’