èªèšŒ
AuthSafeãOAuth 2.0ãšOpenID Connectã䜿çšããŠãå®å šã§æšæºèŠæ Œã«æºæ ãããã°ã€ã³ããã³ID管çã¯ãŒã¯ãããŒãå®çŸããæ¹æ³ãã芧ãã ããã
èªèšŒãšã¯äœã§ããïŒ
èªèšŒãšã¯ãã¢ããªãã¢ã¯ã»ã¹ãèš±å¯ããåã«ããŠãŒã¶ãŒã誰ã§ãããã確èªããããã»ã¹ã§ãã
AuthSafeã§ã¯ããã®ããã»ã¹ã¯ææ°ã®èªèšŒåºæºã«æºæ ããŠãããã¢ããªã±ãŒã·ã§ã³ãä¿¡é Œã§ããå®å šãªããŒã¯ã³ãçæããŸãã
ãŠãŒã¶ãŒãããªãã®ã¢ããªãããã°ã€ã³ãéå§ããŸãã
AuthSafeã¯ãèšå®ããããã°ã€ã³æ¹æ³ãéããŠæ¬äººç¢ºèªãè¡ããŸãã
AuthSafeã¯ããŒã¯ã³ãšIDã¯ã¬ãŒã ãçºè¡ããŸãã
ããªãã®ã¢ããªã¯ãä¿è·ããããªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãèš±å¯ããŸãã
èªèšŒãããŒ
AuthSafeã¯ããã©ãŠã¶ããã³ã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³åãã«èªå¯ã³ãŒãïŒPKCEãå®è£ ããŠãããå®å šãªããŒã¯ã³äº€æã¯ããã¯ãšã³ãã§åŠçãããŸãã
OAuth 2.0ãšOpenID Connect
OAuth 2.0
ã¢ã¯ã»ã¹ããŒã¯ã³ãšã¹ã³ãŒãã䜿çšããå§ä»»èªèšŒãæäŸããããšã§ãã¢ããªããŠãŒã¶ãŒãã¹ã¯ãŒããæ±ãããšãªãAPIã«ã¢ã¯ã»ã¹ã§ããããã«ããŸãã
OpenID Connect (OIDC)
OAuth 2.0ã®äžã«IDããŒã¯ã³ãšãŠãŒã¶ãŒã¯ã¬ãŒã ã«ããIDèªèšŒæ©èœã远å ããæšæºèŠæ Œã«åºã¥ããèªèšŒãå¯èœã«ããŸãã
ããŒã¯ã³ã®çš®é¡
ã¢ã¯ã»ã¹ããŒã¯ã³
ã¯ã©ã€ã¢ã³ããä¿è·ãããAPIãåŒã³åºãããã«äœ¿çšãããæå¹æéã®çãããŒã¯ã³ã
IDããŒã¯ã³
ã¢ããªã±ãŒã·ã§ã³ã«ãããèªèšŒç¶æ ã瀺ããŠãŒã¶ãŒã¯ã¬ãŒã ãå«ãIDããŒã¯ã³ã
ãªãã¬ãã·ã¥ããŒã¯ã³
æå¹æéã®é·ãããŒã¯ã³ã§ããŠãŒã¶ãŒãå床ãã°ã€ã³ããããšãªãæ°ããã¢ã¯ã»ã¹ããŒã¯ã³ãååŸããããã«äœ¿çšãããŸãã
ã»ãã¥ãªãã£ç®¡ç
AuthSafeã¯ãããŒã¯ã³ã®çºè¡ã転éãæ€èšŒã«ãããŠãå€å±€çãªä¿è·æ©èœãæäŸããŸãã
PKCEïŒS256ïŒã¯èªå¯ã³ãŒããããŒã«ãããŠå¿ é ã§ãã
ããŒã¯ã³ã¯çœ²åãããŠãããJWKSãéããŠæ€èšŒããå¿ èŠããããŸãã
HTTPSã®ã¿ã䜿çšãããªãã€ã¬ã¯ããšAPIéä¿¡ã䜿çšããŠãã ããã
ããŒã¯ã³ã®æå¹æéãšããŒããŒã·ã§ã³ã«é¢ããããªã·ãŒã培åºããã
次ã®ã¹ããã
APIãšã³ããã€ã³ã
æ¬çªç°å¢ãžã®çµ±åã«åããŠãèªèšŒãããŒã¯ã³ãããã³ãŠãŒã¶ãŒæ å ±ãšã³ããã€ã³ãã確èªããŠãã ããã
ãšã³ããã€ã³ããªãã¡ã¬ã³ã¹ã衚瀺 ->ã¯ã€ãã¯ã¹ã¿ãŒã
ã¬ã€ãä»ãã®ã»ããã¢ããæé ã«åŸãã°ãæ°åã§AuthSafeãã¢ããªã«çµ±åã§ããŸãã
ã¯ã€ãã¯ã¹ã¿ãŒããéã ->