Beyond OAuth: Navigating the Complexities of User and Group-Focused Authorization in Modern Applications
Facebook X LinkedIn

Beyond OAuth: Navigating the Complexities of User and Group-Focused Authorization in Modern Applications

Combined Session
Wednesday, May 10, 2023 15:10—15:30
Location: A 05-06

Authorization in modern applications is becoming increasingly complex, particularly when it comes to managing access to resources at the individual user and group levels. OAuth has become a widely-used standard for granting access to resources on behalf of a user, but it is not well-suited for these more nuanced use cases. In this talk, we will explore the confusion surrounding the use of OAuth for user and group-focused authorization in applications. We will discuss the standard meaning of authorization in OAuth, which is to grant access for an application to call APIs on behalf of the user, and how misusing OAuth for this purpose can lead to bad architecture and bloated JWT tokens. We will also introduce alternative standards like UMA (User-Managed Access) and GNAP (Group-Based Nested Access Protocol) as potential solutions for user and group-controlled resource delegation. These standards provide a more fine-grained and dynamic approach to access control and can be integrated with policies created by a PBAC (Policy-Based Access Control) server for a more comprehensive solution. Attendees will leave with a better understanding of the limitations of OAuth for user and group-focused authorization, and with a clear understanding of the potential of UMA and GNAP as solutions for these use cases.

Navigating the Complexities of User and Group-Focused Authorization in Modern Applications
Event Recording
Navigating the Complexities of User and Group-Focused Authorization in Modern Applications
Click here to watch the recording of this session. Please note that this video is only available to event participants and subscribers. You'll need to log in to watch it.
Beyond OAuth: Navigating the Complexities of User and Group-Focused Authorization in Modern Applications
Presentation deck
Beyond OAuth: Navigating the Complexities of User and Group-Focused Authorization in Modern Applications
Click here to download the slide deck. Please note that downloads are only available for event participants and subscribers. You'll need to log in to download it.
Aarthi Raghavendra
Aarthi Raghavendra
EmpowerID
Aarthi Raghavendra is a seasoned software architect and product manager with over 10 years of experience in the industry. She holds a Master's degree in Computer Science from the University of...
Subscribe for updates
Please provide your email address