OAuth 2.0 完全指南:Authorization Code Flow 與實作安全清單

讓學習者理解 OAuth 2.0 的 authorization 本質,並能避開常見的實作安全坑(token 儲存、scope 設計、PKCE)

3 sections · 6 lessons

Course outline

OAuth 2.0 基礎概念

  1. Authorization 與 authentication 的差別
  2. OpenID Connect 在 OAuth 之上的角色

Authorization Code Flow 實作

  1. Authorization code 換 access token 的流程
  2. Access token 與 refresh token 的儲存原則

實作安全清单

  1. Scope 設計原則
  2. PKCE 為何所有 client 都該用

Start learning with Wondering