DiazCarrete, to random
@DiazCarrete@hachyderm.io avatar

Learning about user Authentication with OAuth 2.0
https://oauth.net/articles/authentication/
(I unironically like this post, it has cleared some confusion for me.)

tbroyer, to Java
@tbroyer@piaille.fr avatar

connect2id's Nimbus OAuth2/OIDC SDK is underrated, particularly as a direct dependency!

https://connect2id.com/products/nimbus-oauth-openid-connect-sdk

Many people use it through Spring Security or Pac4j but the lib is relatively easy to use directly (particularly if you know the protocols) and can be used to add OIDC support to Java apps with much less complexity than those Spring or Pac4j authentication frameworks (but at the cost of having to handle some of the Web security yourself, mainly around CSRF)

#Java #OAuth2 #OIDC #OpenIDConnect #SpringSecurity #Pac4j

mattcen, to email
@mattcen@aus.social avatar

In principle, I support the use of #OAuth2 for #IMAP/#SMTP authentication; I just wish it didn't make it so much harder to use my preferred mail clients for corporate #email accounts because each client's OAuth2 app key needs to be approved by the sysadmin.

Currently cranky that I can't use Mutt with a couple of O365 accounts, and wondering if I can do something sneaky like rip OAuth2 keys out of Thunderbird or something.

naturzukunft, to fediverse German

Is there a rdf vocab for oauth2 properties like userId? I want to extend an actors profile with the oauth2 providers userId.

Osunderdog, to random

Weekend plans!

I'm messing around with #oauth2 on google. I want to do some of my own picture investigations.

I finally was able to retrieve 'mediaItems'. Now on to ingesting them into a little database... I think I'm going to go with #duckdb. Just because I need some experience with it.

Might as well use #sqlachemy so I can be reminded how much I dislike it.

cliffwade, to fediverse
@cliffwade@allthingstech.social avatar

Good morning and happy Sunday to the

How's your day going so far? Tell me what you've accomplished or what you hope to accomplish.

For me, I'm starting the day off my usual S'mores flavored iced coffee and just going to rest and relax. Yesterday was a very lazy day and I hope to do more of the same today.

Osunderdog,

@cliffwade I am finally rested up from a week of work related travels. Got all my home chores done.

Today I'm going to brew some wonderful coffee and go exploring OAuth2 and the Google Photos API.

Exciting stuff.

till, to firefox

#OpenPrinting as a part of the #LinuxFoundation is participating in the 20th #GSoC, #GSoC2024!!

https://wiki.linuxfoundation.org/gsoc/google-summer-code-2024-openprinting-projects

We have lots of amazing project ideas this year:

Contact us ASAP to get onboarded at OpenPrinting and to work out your proposal.

everythingopen, to RedHat
@everythingopen@fosstodon.org avatar

Continuing our #EverythingOpen Schedule highlights, we present Fraser Tweedale @hackuador from #RedHat who will be presenting on Passwordless #Linux using #FreeIPA.

Fraser will cover how distributed #authentication has evolved, and the place of technologies like #FIDO2 #passkeys and external #OAuth2 providers in the new landscape.

Schedule 🔜

Registrations now open:
https://2024.everythingopen.au/news/registrations-open/

thunderbird, to random
@thunderbird@mastodon.online avatar

If you use Thunderbird as a client for Microsoft-owned accounts and have sign-in issues, especially recently, be sure to check our newly updated KB article on the topic. https://support.mozilla.org/en-US/kb/microsoft-oauth-authentication-and-thunderbird-202

We'll be keeping a close eye on these issues, and thanks to everyone who has both let us know about their problems and jumped in to help others. 😊 💙

#Thunderbird #Outlook #OAuth2

davecykl,

@thunderbird Having been through this process at work recently, it seems that a possible cause of problems could be #Thunderbird not being set up to allow cookies (which privacy conscious users naturally tend not to permit). It seems that some #OAuth2 login pages may need cookies to be allowed in order to work, so it is probably worth adding this to the support page as a suggestion to check this setting.

hertg, to security

Question for the and people.

For user accounts that have enabled multifactor authentication, how do you handle self-service password resets? On online platforms, it is usually possible to reset the password via email. I think that is fine for accounts that don't use multifactor authentication. But what if a user logs in with their phone number (They have no email, just the phone) and use text message as their second factor? Sending a password reset code via text message would be a bit stupid. This would mean that the user doesn't really have two-factor authentication if you can reset the first-factor with the second-factor.

I do currently not allow self-service password resets if a user has multifactor enabled. They are required to get in contact with customer support in that case. For our use-case this is ok, but it's obviously not very user-friendly. However, I don't really see a solution in the case where the phone number is the primary identifier and second-factor. I am interested in some thoughts on the topic.

robustjumprope, to androiddev

I've been learning Android development the last week or so since I finally switched over to Android for my main device. For the most part, I understand how it works and feel like I've made progress.

But right now I feel kinda stuck. I haven't been able to find a good tutorial for using oauth in an app. I've tried looking at various open source projects for examples, but I'm still confused. Does anyone in the AndroidDev world know anything that might help?

hrefna, to random
@hrefna@hachyderm.io avatar

Ughhhhhh, okay, there doesn't appear to be an actively maintained #OAuth2 client for #OCaml.

That's not currently a problem and won't be for a bit, but may require some work later.

JasonPester, to random
@JasonPester@mastodon.social avatar

Quick FYI 🏁 🏎️

Prior to #GoDaddy killing my #POP #Email client access on June 2 as part of #Microsoft's mandate to force users onto its #Exchange protocol, I switched from #Outlook 2016 to #Thunderbird 114 Beta (which still connects w/ #POP3 + #OAuth2 - unsure if it's a glitch, but it works)

Thunderbird 114 Beta Portable (it's the version I'm using)
https://portableapps.com/apps/internet/thunderbird_portable/test

Since Thunderbird team is moving towards its new #Supernova #UI for Thunderbird 115, there's a mixture of old & new menus

gisgeek, to random
@gisgeek@floss.social avatar

At work, we recently migrated to MS 365 for part of our email management and I discovered a tiny useful piece of software that simplifies for me the OAUTH2 based idiosyncratic system of Outlook and its friends.

A proxy now allows me to still use mutt, fetchmail, msmtp and exim to read and write emails.

https://github.com/simonrob/email-oauth2-proxy

#oauth2 #outlook #proxy

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • ngwrru68w68
  • everett
  • InstantRegret
  • magazineikmin
  • thenastyranch
  • rosin
  • Durango
  • ethstaker
  • Youngstown
  • slotface
  • khanakhh
  • kavyap
  • DreamBathrooms
  • Leos
  • osvaldo12
  • tacticalgear
  • cubers
  • cisconetworking
  • anitta
  • provamag3
  • modclub
  • mdbf
  • GTA5RPClips
  • tester
  • megavids
  • normalnudes
  • lostlight
  • All magazines