|
所在平台: Udemy |
课程主页: https://www.udemy.com/course/oauth2-and-oidc-demystified/
课程评论:没有评论
## OAuth2 与 OIDC 深入解析:基于 Keycloak 的实践运用 **课程概览:** 本课程旨在帮助您深入理解 OAuth2 和 OIDC 的核心概念与关键细节,从而在实际应用中高效运用这些协议。本课程内容精炼,注重实效,以节省您的宝贵时间。您可以根据需要重复观看重点内容,以获得更深刻的理解。 **您将学到:** * **核心概念与术语:** 掌握 OAuth2 和 OIDC 的基础构成,包括角色、令牌 (tokens) 和作用域 (scopes)。扎实的基础将是您后续深入学习的基石。 * **授权流程:** 学习并理解不同 OAuth2 授权流程,包括:授权码流程 (Authorization Code with PKCE)、客户端凭据流程 (Client Credentials)、设备授权流程 (Device Code)、刷新令牌流程 (Refresh Token)、隐式流程 (Implicit) 和密码流程 (Password)。了解何时以及为何选择使用每种流程,以满足不同的应用需求和安全要求。 * **底层 OAuth2:** 通过发送原始 HTTP 请求来实践 OAuth2 流程。理解 OAuth2 协议的底层运作机制(而非仅仅依赖库),将有助于您更好地排查问题并确保通信安全。 **目标受众:** 本课程适合希望深入了解 OAuth2 和 OIDC 的开发人员、架构师和 IT 专业人士。无论您是正在集成第三方认证提供商、保护 API,还是仅仅希望更好地理解这些技术,本课程都将为您提供有价值的内容。 **先修要求:** 具备 HTTP 协议基础知识,并最好有软件开发经验。 **课程声明:** 本课程**并非**关于如何使用和配置 Keycloak 或任何其他身份提供商的教程,也**并非**关于如何使用认证库的教程。本课程的**主要目标**是让您理解 OAuth2 协议,其工作原理以及如何运用它。 **课程目标:** 完成本课程后,您将对 OAuth2 和 OIDC 有扎实的掌握,并能自信地选择最适合您需求的授权流程。 加入我们,一起揭开 OAuth2 和 OIDC 的神秘面纱,将您的认证技术提升到新的高度!
Welcome to "OAuth2 and OIDC Demystified". This course is designed to equip you with a deep understanding of the core concepts and essential details needed to effectively use OAuth2 and OIDC in real-world scenarios. It is intentionally short and to the point, since I value your time. You can always re-watch some parts if you find them harder to understand, and I recommend you to do that.What You'll Learn:Core Concepts and Terminology: Fundamental components of OAuth2 and OIDC, including roles, tokens and scopes. Understanding these basics will serve as the foundation for everything you do with OAuth2 and OIDC.Authorization Flows: Learn the different OAuth2 flows: Authorization Code (PKCE), Client Credentials, Device Code, Refresh Token, Implicit and Password. Discover when and why you should use each one, depending on your application's needs and security requirements.Low-Level OAuth2: Test OAuth2 flows using raw HTTP requests. By understanding how OAuth2 flows work on low-level (instead of using libraries), you'll be better prepared to troubleshoot issues and ensure secure communication.This course is intended for developers, architects, and IT professionals who are looking to deepen their knowledge of OAuth2 and OIDC. Whether you are integrating third-party authentication providers, securing APIs, or simply wanting to understand the technology better, this course has something for you.You should have a basic understanding of HTTP protocol and some experience in software development is desirable.This is NOT a course on how to use and configure Keycloak or any other identity provider, and this is NOT a course on how to use authentication libraries. The main goal is to understand OAuth2 protocol, how it works and how to use it.By the end of this course, you will have a strong grasp of OAuth2 and OIDC and be confident in choosing the right authorization flows.Join us on this journey to demystify OAuth2 and OIDC and take your authentication skills to the next level!