24. OAuth 2.0: Explained with API Request and Response Sample | High Level System Design

Поділитися
Вставка
  • Опубліковано 26 вер 2024

КОМЕНТАРІ • 64

  • @deepak-ku9qq
    @deepak-ku9qq 8 місяців тому +6

    you videos made LLD and HLD so simple for me !!

  • @SandeepAS-ov3fk
    @SandeepAS-ov3fk 2 місяці тому +1

    noone can explain Oauth like you

  • @shubhamagarwal1434
    @shubhamagarwal1434 4 місяці тому +2

    Congrats on your 100k Subscribers...

  • @gowtham4383
    @gowtham4383 6 місяців тому +1

    Great. Thank you for the Clear and Simple Explanation

  • @DurgaShiva7574
    @DurgaShiva7574 8 місяців тому +3

    Eagerly Waiting for JWT video, as well as Spring boot implementation for O-AUTH as well as JWT from you.

  • @shubhamrajput37
    @shubhamrajput37 8 місяців тому +5

    Waiting for Spring Boot videos as covered all the topics of Java and LLD, currently going through HLD

  • @balakrushnabehera2800
    @balakrushnabehera2800 8 місяців тому +1

    Best explanation ever on OAuth❤❤

  • @dhivyaviswanathan7604
    @dhivyaviswanathan7604 8 місяців тому +1

    Recently I bought your LLD course from Udemy .The effort is awesome but the thing is some video's are in Hindi its hard to understand since I am from south. Please make upcoming videos in English so that everyone can make use of it.Thanks shreyansh.

  • @adityaallam
    @adityaallam Місяць тому +1

    Hi Sir, great video! I have a question, all the sensitive information(client id, client secret, username, password) is sent via query parameters, how is security ensured so that these information is not stolen? Thanks in advance!

  • @koteshwarraomaripudi1080
    @koteshwarraomaripudi1080 8 місяців тому +3

    For csrf, google could issue token only if the client that is requesting the token is matching with the client id that the code was given to

  • @prateek2159
    @prateek2159 3 місяці тому +1

    Hi Shrayansh, I think there is some mistake in the CSRF attack workflow here. When Insta sends request to the resource server with authorization_code (of the attacker), redirect_uri, id and secret the resource server after validation of the code sends the response with the requested data to the redirect_url (which is insta’s uri because this is what was present in the request) not the attacker. Just with the authorization code of the attacker, there is no way for the resource server to send the data to the attacker.

  • @shubhamjumde9076
    @shubhamjumde9076 4 місяці тому

    When there is inter service communication, like Order service calls Delivery service, how OAuth is implemented? What would be resource owner, authentication server and all?
    This video very well explains OAuth and helped me to understand OAuth . Thank you!

  • @kartikeyrana3736
    @kartikeyrana3736 8 місяців тому +1

    eagerly waiting for the Springboot implementation !

  • @gauravraj2604
    @gauravraj2604 7 місяців тому +1

    Hey Shreyansh,
    Do you have any plan to create a video on fetching thread dump and analysing it for debugging purposes ?
    Please reply if you see this. I have asked multiple things on different videos but unfortunately could not get reply to any.

  • @khushgandhi6638
    @khushgandhi6638 8 місяців тому +1

    Hey shreyansh , how many videos are pending for the hld playlist?

  • @ramprasadthakur1682
    @ramprasadthakur1682 4 місяці тому

    Hi Shreyansh In CSRF attack attacker can know my state value as it's passed in request param if he intercepts my request he will get access to it as well right?

  • @sitikantapanigrahi8621
    @sitikantapanigrahi8621 7 місяців тому +1

    Hello bhaiya. I have one query. Should i have to pay monthly if i join the membership.

  • @vikasrai4915
    @vikasrai4915 8 місяців тому

    Hello Shreyansh, I have been following since more than a year now, I have been binge watching your videos earlier even when I wasn't interviewing, a few months back I had some health issue and I had to take break from my work, now I am preparing for interviews and I am trying to watch your playlist, few videos are member only, and you also have a course on udemy, so my question is, Is your course on udemy and the playlist on youtube(with membership) any different or they both are same ? If not same what are the differences? Regards.

    • @ConceptandCoding
      @ConceptandCoding  8 місяців тому

      its same just for engineers who prefer udemy over youtube.

  • @gauravraj2604
    @gauravraj2604 8 місяців тому

    Hey Shrayansh, posting 1 question related to LLD / HLD interview.
    1. How are we supposed to create those block diagrams and demonstrate during interview? Asking as I can see interviewee is using some software in one of the mock interviews you took which might not be possible for others.
    2. Also does it depend oncompany to company whether they will select an interviewee when he was unable to submit working code though was able to convey uml diagram?

  • @ShashikantPawar-g5u
    @ShashikantPawar-g5u 7 місяців тому

    Can you cover use cases of each grant type

  • @harshitgoel6612
    @harshitgoel6612 8 місяців тому +1

    when can we expect spring boot series ?

    • @ConceptandCoding
      @ConceptandCoding  8 місяців тому +1

      by this month i will share the roadmap, thats my plan

  • @harshitagarwal2682
    @harshitagarwal2682 2 місяці тому +1

    👍👍

  • @ShubhamRajput23
    @ShubhamRajput23 8 місяців тому

    Hello Shreyansh,
    Regarding the authorization & token request, video mentions to include the redirect URI in the query parameter. Typically, for each REST API POST call, we expect a response. Could you clarify whether the authorization code will be included in the REST API call response, or if it will be sent separately by the authorization server via a webhook call to the client's redirect URI? If it is indeed a webhook call, does the client also need to expose an endpoint to receive the authorization code? I'm curious about the industry standard in this context.

    • @ConceptandCoding
      @ConceptandCoding  8 місяців тому

      The authorization code is included in the redirect URI as a query parameter in the response to the authorization request.
      The client needs to expose an endpoint (the redirect URI) to receive and handle the authorization code.
      There is no industry standard for delivering the authorization code via webhook; it's typically delivered directly to the client's specified redirect URI
      I would say, this is generally for security purpose.

  • @AbhishekKumar-kk6qs
    @AbhishekKumar-kk6qs 8 місяців тому

    Hi shreyansh,
    Can you please suggest some books which u follow for learning these cool backend technology.

    • @ConceptandCoding
      @ConceptandCoding  8 місяців тому

      generally i go with official documentation buddy

  • @tejasshaha6629
    @tejasshaha6629 8 місяців тому

    Nice video. 1 question. For /authorization api why we are using GET request ? What if Gmail want to create/update entry at their side to make sure who has asked for code/token then it should be POST request right ?

    • @ConceptandCoding
      @ConceptandCoding  8 місяців тому

      nice catch Tejas.
      i think this design choice might be done because of simplicity or ease of integration.
      But you know, this do post the security issues (usage of GET call) .
      So thats why Authorization code grant type with PKCE is nowadays recommended which try to mitigate this exposure of authorization code in previous GET call.
      i think i should cover that too.

    • @tejasshaha6629
      @tejasshaha6629 8 місяців тому

      @@ConceptandCoding Sure sir. Thank you for the explanation.

  • @user-zp1dv4yh5e
    @user-zp1dv4yh5e 8 місяців тому +1

    Can you also make it for Azure AD Oauth?

    • @ConceptandCoding
      @ConceptandCoding  8 місяців тому +1

      noted

    • @kazcode1937
      @kazcode1937 8 місяців тому

      @@ConceptandCoding what is difference btw authorization and authentication?

  • @dianadaniels4304
    @dianadaniels4304 7 днів тому

    Miller Jason Lopez Edward Perez Barbara

  • @varunaggarwal7126
    @varunaggarwal7126 3 місяці тому

    I am working in a fortune 20 company and everywhere they have implemented implicit grant 😂

  • @nazimuddinasif5489
    @nazimuddinasif5489 8 місяців тому +1

    It is possible to get this note?

  • @meghadave9363
    @meghadave9363 6 місяців тому

    Hi is it possible for you to add gpay payment option for your course. please

    • @ConceptandCoding
      @ConceptandCoding  6 місяців тому

      i think in mobile app you will get that

    • @meghadave9363
      @meghadave9363 6 місяців тому

      @@ConceptandCoding payment is falling for all options

    • @meghadave9363
      @meghadave9363 6 місяців тому

      @@ConceptandCoding tried Gpay on app, credit card also, it's failing

  • @saideepak1740
    @saideepak1740 8 місяців тому

    @Shreyansh please share notes🙏

    • @ConceptandCoding
      @ConceptandCoding  8 місяців тому

      sorry i was out this weekend, will do it tomm for sure

    • @ConceptandCoding
      @ConceptandCoding  8 місяців тому

      notebook.zohopublic.in/public/notes/bietv949cfd82a5804e0ea1d18400d3ff6fa3

    • @saideepak1740
      @saideepak1740 8 місяців тому

      Thankyou shreyansh

  • @StephenGunter-u2c
    @StephenGunter-u2c 7 днів тому

    Young Dorothy Lopez Mary White Charles

  • @JuliaAnne
    @JuliaAnne 8 днів тому

    Thompson Sarah Young David Miller Angela

  • @DavidRockwell-k5l
    @DavidRockwell-k5l 12 днів тому

    Miller Linda Williams Nancy Gonzalez Sarah

  • @ZoeJohnston-k8o
    @ZoeJohnston-k8o 11 днів тому

    Thomas Elizabeth Moore Melissa White Ronald

  • @ratansarkar7444
    @ratansarkar7444 8 місяців тому

    AK din ke liye videos free kar do na vaiya

  • @whoshyam
    @whoshyam 24 дні тому

    notes link please ?

  • @StephenGunter-u2c
    @StephenGunter-u2c 11 днів тому

    Brown Matthew Gonzalez John Moore William

  • @Loki-vy5vg
    @Loki-vy5vg 5 місяців тому

    I doubt what you taught, can you please share resources I can refer to and verify 🙏

    • @ConceptandCoding
      @ConceptandCoding  5 місяців тому +1

      pls check original documentation of OAuth2.0 RFC

  • @anshumansingh6336
    @anshumansingh6336 8 місяців тому

    where are the notes...references..

    • @ConceptandCoding
      @ConceptandCoding  8 місяців тому +1

      oops my bad, will add the notes link in description section by EOD

    • @Dlk9407
      @Dlk9407 8 місяців тому

      @@ConceptandCodingpls add bro