Asm*_*kim 5 security oauth-2.0 jwt asp.net-web-api
我正在浏览Oauth2文档,并认为这是一种宽容的安全性,因此我尝试使用特殊方案实现JWT令牌,如图片中的移动应用程序与Web API进行通信.
注意:我不喜欢Oauth2刷新令牌的想法,因为它们可能会被盗并允许并行使用(由合法和恶意用户),除非您通过旋转它们来实施盗窃检测(在每次请求时刷新刷新令牌),在这种情况下为什么要使用它们?
身份验证流程如何工作:
问题是:
OAuth2 refresh tokens are not meant to be used by mobile clients. Using refresh tokens requires client credentials, which cannot be stored securely in a mobile application.
Refresh tokens are used from confidentials clients (server side web applications for example). They are often renewed when used (server sends back new access and new refresh token). In contrast to access tokens, the refresh token is only sent to the authorization server, not the resource (API) server.
Regarding your auth flow. Step 2 is the weak link IMO. You allow the client to use an expired token to generate a new access token. So if I find your phone and access the device, it will allow me to get a fresh access token and impersonate you.
You could force the client to refresh the token every say 15 min., but then you have to define what happens if the app gets closed or the device is turned off? Is it okay to re-authenticate the user again?
| 归档时间: |
|
| 查看次数: |
576 次 |
| 最近记录: |