OAuth & One-Page Apps: Avoiding the Redirect
nicholasjacob.com
OAuth & One-Page Apps: Avoiding the Redirect
1–10 of 16 posts
Re: OAuth & One-Page Apps: Avoiding the Redirect
#2Would you end up writing your own OAuth provider in that case?
Re: OAuth & One-Page Apps: Avoiding the Redirect
#3Re: OAuth & One-Page Apps: Avoiding the Redirect
#4Is there a best practice of doing authentication for single-page apps when you don't want to use an external OAuth provider, since a lot of people don't have Twitter/Facebook accounts? Would you end up writing your own OAuth provider in that case?
For node/Express, passport.js is a good option (but doesn't help you out with the database at all) -- http://passportjs.org/guide/username-password.html
Django has basic user authentication built-in, Ruby on Rails has Devise - https://github.com/plataformatec/devise and AuthLogic - https://github.com/binarylogic/authlogic.
I'd recommend reading the Ruby on Rails security guide about user management to get an idea of some of the challenges in building an authentication system: http://guides.rubyonrails.org/security.html#user-management
If you want to write an OAuth provider here's a great PHP tutorial: http://djpate.com/2011/01/13/how-to-write-a-complete-oauth-p...
Re: OAuth & One-Page Apps: Avoiding the Redirect
#5Is there a best practice of doing authentication for single-page apps when you don't want to use an external OAuth provider, since a lot of people don't have Twitter/Facebook accounts? Would you end up writing your own OAuth provider in that case?
But as I've commented, having built edgeyo and Strangers for Dinner and having tested in-page (iframe) and redirected authentication, redirected authentication seems to garner more trust
Re: OAuth & One-Page Apps: Avoiding the Redirect
#6I open a new window (tab) with the OAuth process and since I opened the tab I can redirect to some quick closing script and my main code is waiting for the auth process to finish. Once it does the user is through. Easy peasy.
Re: OAuth & One-Page Apps: Avoiding the Redirect
#7We, Backup Box, are a one page app and we do OAuth without redirect all the time. In fact we have one script that handles all the OAuth processes and any new ones we need to create just pop in and there's no customization to be done. I open a new window (tab) with the OAuth process and since I opened the tab I can redirect to some quick closing script and my main code is waiting for the auth process to finish. Once i…
Re: OAuth & One-Page Apps: Avoiding the Redirect
#8We, Backup Box, are a one page app and we do OAuth without redirect all the time. In fact we have one script that handles all the OAuth processes and any new ones we need to create just pop in and there's no customization to be done. I open a new window (tab) with the OAuth process and since I opened the tab I can redirect to some quick closing script and my main code is waiting for the auth process to finish. Once i…
Presumably you have the auth flow in the new tab finish on a simple page containing a script. What does that script do to notify the original window that the auth flow is finished?
Re: OAuth & One-Page Apps: Avoiding the Redirect
#9Earlier quoted context omitted.
Presumably you have the auth flow in the new tab finish on a simple page containing a script. What does that script do to notify the original window that the auth flow is finished?
If you open the OAuth flow in a pop-up, with window.open (actually, for most browsers to open a pop-up, the user has to actually click on a link, so your href should be javascript:window.open(" https://oauth_start ) - target="_blank" might work as well but I can't remember), after the user has completed the authentication and ended back up on your site, you can trigger a function on the parent window and close the po…