3min chapter

Software Engineering Radio - the podcast for professional software developers cover image

Episode 376: Justin Richer On API Security with OAuth 2

Software Engineering Radio - the podcast for professional software developers

CHAPTER

How Does Dropbox Prove It's Legitimate?

When OAuth 1 was written, it was assumed that all client applications and all authorization servers would have access to effectively shared secrets. When OAuth 2 at least admitted that not all client applications are able to do that. All of that gets bundled up into this access token, which is what then gets handed back to the client. But the API needs to be able to support that level of granularity.

00:00

Get the Snipd
podcast app

Unlock the knowledge in podcasts with the podcast player of the future.
App store bannerPlay store banner

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode

Save any
moment

Hear something you like? Tap your headphones to save it with AI-generated key takeaways

Share
& Export

Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more

AI-powered
podcast player

Listen to all your favourite podcasts with AI-powered features

Discover
highlights

Listen to the best highlights from the podcasts you love and dive into the full episode