|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/oauth-2-simplified/
课程评论:没有评论
课程名称:OAuth 2.0 基础知识 概述:OAuth 2.0 已成为提供安全访问网络 API 的行业标准,使应用程序能够在不危害安全的情况下访问用户数据。全球各地的公司将 OAuth 添加到其 API 中,以便从自己的移动应用程序和第三方物联网设备安全访问,甚至访问银行 API。本课程由安全专家 Aaron Parecki 主讲,全面解析了每种 OAuth 流程(授权类型),并将其应用于如网页应用、原生应用和单页面应用等用例。 在学习如何让应用程序使用 OAuth 访问 API 的同时,您还将学习如何使用 OpenID Connect 获取用户身份。如果您正在构建 API,将了解不同访问令牌格式之间的差异和权衡,如何选择合适的访问令牌生命周期,以及如何设计作用域以保护 API 的各个部分。本课程还包含 OAuth 工作组的最新建议,涵盖了从使用 PKCE 适用于所有类型的应用,到解释为什么将隐式和密码授权从规范中去除的动机。这些安全建议和更多内容将汇总到新的 OAuth 2.1 更新中,因此本课程将为您提供学习如何最佳使用 OAuth 的良好开端。 课程结束时,您将理解: - OAuth 产生的背景和解决的问题 - OAuth 2.0 和 OpenID Connect 的基础知识 - 开发基于网络和原生 OAuth 应用的最佳实践 - 本地和远程访问令牌验证的区别 - 如何验证 JWT 访问令牌 您将能够: - 从零开始实现 OAuth 客户端 - 保护原生和 JavaScript 应用中的 OAuth 流程 - 使用 OpenID Connect 获取用户的姓名和电子邮件地址 - 使用 OAuth 访问令牌保护 API - 设计作用域以保护 API 的不同部分 本课程适合: - 软件架构师、应用程序开发人员或技术决策者 - 从事 API、网络应用、移动应用或微服务工作的人士 - 希望加深对应用安全理解并成为技术领导者的人士 先决条件: - 对 HTTP 请求、响应和 JSON 有基本了解 - 不需要编程语言知识,因为练习可以在不编写任何代码的情况下完成 - 需要 Postman、curl 或其他 HTTP 客户端的经验 - 需要一个免费的 Auth0 开发者帐户 本课程还为您提供独家访问一个互动的基于网页的工具,该工具将引导您完成练习,并在过程中提供反馈!就像在您进行练习时,讲师为您提供实时反馈一样!
OAuth 2.0 has become the industry standard for providing secure access to web APIs, allowing applications to access users' data without compromising security. Companies around the world add OAuth to their APIs to enable secure access from their own mobile apps and third-party IoT devices and even access to banking APIs.Security expert Aaron Parecki breaks down each of the OAuth flows (grant types) and applies them to use cases such as implementing OAuth for web apps, native apps, and SPAs. In addition to learning how applications can use OAuth to access APIs, you'll learn how to use OpenID Connect to get the user's identity.If you're building an API, you'll learn the differences and tradeoffs between different access token formats, how to choose an appropriate access token lifetime, and how to design scopes to protect various parts of your APIs.This course includes the latest recommendations from the OAuth working group including covering everything from using PKCE for all types of applications to explaining the motivations behind dropping the Implicit and Password grants from the spec. These security recommendations and more will be rolled up into the new OAuth 2.1 update, so this course will give you an excellent head start on learning the best way to use OAuth going forward!By the end of this course, you'll understand:The problems OAuth was created to solveThe basics of OAuth 2.0 and OpenID ConnectBest practices for developing web-based and native OAuth appsThe difference between local and remote access token validationHow to validate JWT access tokensAnd you'll be able to:Implement an OAuth client from scratchProtect the OAuth flows in native and JavaScript appsUse OpenID Connect to get the user's name email addressProtect an API with OAuth access tokensDesign scopes to protect various parts of your APIThis course is for you because...You're a software architect, application developer, or technical decision makerYou work with APIs, web apps, mobile apps, or microservicesYou want to deepen your understanding of application security and become a technical leaderPrerequisitesA basic understanding of HTTP requests, responses, and JSONNo programming language knowledge is necessary since the exercises can be completed without writing any code!To follow along with the exercises, you'll also need:Experience with Postman, curl, or any other HTTP clientA free Auth0 Developer accountThis course also gives you exclusive access to an interactive web-based tool that will guide you through the exercises and give feedback along the way! It's like having the instructor provide real-time feedback as you are working through the exercises!