oauth-wg / oauth-v2-1

OAuth 2.1 is a consolidation of the core OAuth 2.0 specs
https://oauth.net/2.1/
Other
52 stars 27 forks source link

Prohibition of using OAuth for user authentication #146

Closed ritou closed 1 day ago

ritou commented 1 year ago

Despite the specification explicitly stating "This is an Authorization Framework" as of OAuth 2.0, some Authorization Server/Resource Server and many Client developers have been using this for the purpose of user authentication. In order to avoid the occurrence of vulnerabilities and the lack of interoperability, I hope to include the following sentences:

aaronpk commented 1 day ago

This paragraph is new in OAuth 2.1 which clarifies the details https://www.ietf.org/archive/id/draft-ietf-oauth-v2-1-12.html#section-1-7