Show Navigation
Conversation
Notices
-
>Look at the drafts of OAuth 2.1 and OAuth 3
As far as I recall the creator of OAuth quit from the team made for OAuth 2 because it was garbage and he didn't want to participate in something that can't be sanely secure.
-
@mangeurdenuage It was more than one person that left the #OAuth 2.0 project, claiming the design was too complex to be reliably secure. Implementing it was notoriously difficult to get right. But now, we rely on premade libraries that we assume to be "secure enough".