InfoQ

News

OAuth Gaining Momentum

Posted by Charles Humble on Jun 10, 2008 04:00 PM

Community
Java,
SOA
Topics
Security
In a recent blog post Jeff Altwood of Coding Horror fame described an increasingly common, but highly undesirable, practice amongst web site developers; that of asking for your email user name and password so that the service can look through your email contacts to see if any of your contacts also use the service. Jeff illustrates this using Yelp, but he could just as well have used LinkedIn (see below) or any number of other web sites.
LinkedIn - Build your network

 

In typically forthright style, Jeff goes on to highlight why this is such a problem. In short “they have effectively asked for the keys to my house in order to riffle through my address book.”

A number of companies and individuals are working on solutions to this problem including Google, Yahoo and Microsoft, as well as the OAuth project. Initiated by Blaine Cook, Chris Messina, Larry Halff and David Recordon, OAuth aims to provide an open standard for API access delegation. The OAuth discussion group was founded in April 2007 to provide a mechanism for this small group of implementers to write the draft proposal for the protocol. During development significant contributions were received from Eran Hammer-Lahav and Google's DeWitt Clinton. The version 1.0 specification was formally released on December 4th 2007.

At a high level OAuth works as follows:

  1. Your site has established a relationship with various webmail service providers.
  2. You share a pass-phrase, or a public key, that you can use to gain access to the web contacts.
  3. You re-direct the user to the login page for their webmail service provider.
  4. The user signs in and tells the webmail service provider that is OK for your site to access their address book.

OAuth is already gaining considerable momentum, with implementations for many popular languages including Java, C#, Objective-C, Perl, PHP and Ruby. The majority of these implementations are hosted by the OAuth project via a Google Code repository. Ryan Heaton has implemented OAuth for Spring security which can be found here. Sites supporting OAuth include Twitter, Ma.gnolia and Google (Alpha launch post here).

No comments

Watch Thread Reply

Educational Content

Bindings, Platforms, and Innovation

This presentation focuses on the Internet and separating myth from fact, history from the future, and the mundane from the imaginative. Bob Frankston presents a vision of what could and should be.

Orchestrating Long Running Activities with JBoss / JBPM

This article explores the use of JBoss and jBPM to implement design solutions that effectively address the issue of orchestrating long running activities.

Neo4j - The Benefits of Graph Databases

This presentation covers the use of graph databases as an optimal solution for data that is difficult to fit in static tables, rapidly evolving data or data that has a lot of optional attributes.

Realistic about Risk: Software development with Real Options

This session introduces Real Options and shows how it can help in running your project. Real Options is a decision-making process that can be used to manage risk.

Communication Flexibility Using Bindings

This article discusses the use of bindings on services and references (including the instance of non-configured bindings) as the means to implement SCA communications in a Web and SOA environment.

Writing DSLs in Groovy

After a short introduction to DSLs, Scott Davis plays with the keyboard showing how to approach the creation of a DSL by typing working snippets of Groovy code that get executed.

Scaling Agile with C/ALM (Collaborative Application Lifecycle Management)

IBM Rational and InfoQ present, Scaling Agile with C/ALM, an eBook showing organizations how to become “finely tuned software delivery machines” by enabling team integration and scaling.

Concurrent Programming with Microsoft F#

Amanda Laucher presents a real life enterprise application written in F#. She shows actual code snippets, explaining design decisions and suggesting how to use some of the F# constructs.