Is there anything wrong with manually providing people access tokens and refresh tokens so they don't have to do the OAuth2 dance themselves?How should I ethically approach user password storage for later plaintext retrieval?Why Does OAuth v2 Have Both Access and Refresh Tokens?What is the purpose of the implicit grant authorization type in OAuth 2?Why is there an “Authorization Code” flow in OAuth2 when “Implicit” flow works so well?What is the difference between the OAuth Authorization Code and Implicit workflows? When to use each one?How should I store and revoke OAuth2 authorizations and/or refresh tokens?OAuth2 - unnecessary complexity with refresh tokenClient secret + refreshing the access token in spring oauth2OAuth2 refresh token utilityOAuth2 purpose of refresh token with authorization code

Group riding etiquette

Heat output from a 200W electric radiator?

Are there any to-scale diagrams of the TRAPPIST-1 system?

Find most "academic" implementation of doubly linked list

Normalized Malbolge to Malbolge translator

Looking for a plural noun related to ‘fulcrum’ or ‘pivot’ that denotes multiple things as crucial to success

Adding and Multiplying Elements of a list together

If I said I had $100 when asked, but I actually had $200, would I be lying by omission?

Notice period 60 days but I need to join in 45 days

Is there an in-universe explanation given to the senior Imperial Navy Officers as to why Darth Vader serves Emperor Palpatine?

Why doesn't Starship have four landing legs?

Why is 3/4 a simple meter while 6/8 is a compound meter?

Defending Castle from Zombies

Why does a sticker slowly peel off, but if it is pulled quickly it tears?

Why does Sauron not permit his followers to use his name?

Number of Fingers for a Math Oriented Race

Is it unusual for a math department not to have a mail/web server?

web scraping images

What will be the immediate action by the pilot and ATC if any plane blocks the runway while landing?

Why does AM radio react to IR remote?

How to handle inventory and story of a player leaving

Why didn't Doc believe Marty was from the future?

Can I lend a small amount of my own money to a bank at the federal funds rate?

How could a self contained organic body propel itself in space



Is there anything wrong with manually providing people access tokens and refresh tokens so they don't have to do the OAuth2 dance themselves?


How should I ethically approach user password storage for later plaintext retrieval?Why Does OAuth v2 Have Both Access and Refresh Tokens?What is the purpose of the implicit grant authorization type in OAuth 2?Why is there an “Authorization Code” flow in OAuth2 when “Implicit” flow works so well?What is the difference between the OAuth Authorization Code and Implicit workflows? When to use each one?How should I store and revoke OAuth2 authorizations and/or refresh tokens?OAuth2 - unnecessary complexity with refresh tokenClient secret + refreshing the access token in spring oauth2OAuth2 refresh token utilityOAuth2 purpose of refresh token with authorization code






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty margin-bottom:0;








0















This seems like an odd question, but something I've been pondering.



I have an API that I'd like people to use, but the people using it require a lot of hand holding through the OAuth2 process to get an access token.



Instead of throwing OAuth2 authorization code grant requirements at my users, what I'd like to do is provide them with a web user interface, where they can copy down revocable access tokens and refresh tokens.



Once people have their tokens, they can plug them into their client application and they're away. If tokens need to be revoked, they can be revoked through my web user interface.



For server to server connections, this seems 'safer'?? than OAuth2 password grant because by forcing people to log into a website to get tokens, people are always required to provide a username and password directly to my system. There is less chance of another intermediary system caching credential information in between the client system and mine.



Is my thinking solid on this or is it a little suspect? Part of me feels wrong for allowing users to skip the Oauth2 authorization code flow entirely.










share|improve this question






























    0















    This seems like an odd question, but something I've been pondering.



    I have an API that I'd like people to use, but the people using it require a lot of hand holding through the OAuth2 process to get an access token.



    Instead of throwing OAuth2 authorization code grant requirements at my users, what I'd like to do is provide them with a web user interface, where they can copy down revocable access tokens and refresh tokens.



    Once people have their tokens, they can plug them into their client application and they're away. If tokens need to be revoked, they can be revoked through my web user interface.



    For server to server connections, this seems 'safer'?? than OAuth2 password grant because by forcing people to log into a website to get tokens, people are always required to provide a username and password directly to my system. There is less chance of another intermediary system caching credential information in between the client system and mine.



    Is my thinking solid on this or is it a little suspect? Part of me feels wrong for allowing users to skip the Oauth2 authorization code flow entirely.










    share|improve this question


























      0












      0








      0








      This seems like an odd question, but something I've been pondering.



      I have an API that I'd like people to use, but the people using it require a lot of hand holding through the OAuth2 process to get an access token.



      Instead of throwing OAuth2 authorization code grant requirements at my users, what I'd like to do is provide them with a web user interface, where they can copy down revocable access tokens and refresh tokens.



      Once people have their tokens, they can plug them into their client application and they're away. If tokens need to be revoked, they can be revoked through my web user interface.



      For server to server connections, this seems 'safer'?? than OAuth2 password grant because by forcing people to log into a website to get tokens, people are always required to provide a username and password directly to my system. There is less chance of another intermediary system caching credential information in between the client system and mine.



      Is my thinking solid on this or is it a little suspect? Part of me feels wrong for allowing users to skip the Oauth2 authorization code flow entirely.










      share|improve this question














      This seems like an odd question, but something I've been pondering.



      I have an API that I'd like people to use, but the people using it require a lot of hand holding through the OAuth2 process to get an access token.



      Instead of throwing OAuth2 authorization code grant requirements at my users, what I'd like to do is provide them with a web user interface, where they can copy down revocable access tokens and refresh tokens.



      Once people have their tokens, they can plug them into their client application and they're away. If tokens need to be revoked, they can be revoked through my web user interface.



      For server to server connections, this seems 'safer'?? than OAuth2 password grant because by forcing people to log into a website to get tokens, people are always required to provide a username and password directly to my system. There is less chance of another intermediary system caching credential information in between the client system and mine.



      Is my thinking solid on this or is it a little suspect? Part of me feels wrong for allowing users to skip the Oauth2 authorization code flow entirely.







      security oauth-2.0






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Mar 27 at 21:22









      John DeverallJohn Deverall

      1,92217 silver badges26 bronze badges




      1,92217 silver badges26 bronze badges

























          0






          active

          oldest

          votes










          Your Answer






          StackExchange.ifUsing("editor", function ()
          StackExchange.using("externalEditor", function ()
          StackExchange.using("snippets", function ()
          StackExchange.snippets.init();
          );
          );
          , "code-snippets");

          StackExchange.ready(function()
          var channelOptions =
          tags: "".split(" "),
          id: "1"
          ;
          initTagRenderer("".split(" "), "".split(" "), channelOptions);

          StackExchange.using("externalEditor", function()
          // Have to fire editor after snippets, if snippets enabled
          if (StackExchange.settings.snippets.snippetsEnabled)
          StackExchange.using("snippets", function()
          createEditor();
          );

          else
          createEditor();

          );

          function createEditor()
          StackExchange.prepareEditor(
          heartbeatType: 'answer',
          autoActivateHeartbeat: false,
          convertImagesToLinks: true,
          noModals: true,
          showLowRepImageUploadWarning: true,
          reputationToPostImages: 10,
          bindNavPrevention: true,
          postfix: "",
          imageUploader:
          brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
          contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
          allowUrls: true
          ,
          onDemand: true,
          discardSelector: ".discard-answer"
          ,immediatelyShowMarkdownHelp:true
          );



          );













          draft saved

          draft discarded


















          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55386654%2fis-there-anything-wrong-with-manually-providing-people-access-tokens-and-refresh%23new-answer', 'question_page');

          );

          Post as a guest















          Required, but never shown

























          0






          active

          oldest

          votes








          0






          active

          oldest

          votes









          active

          oldest

          votes






          active

          oldest

          votes




          Is this question similar to what you get asked at work? Learn more about asking and sharing private information with your coworkers using Stack Overflow for Teams.







          Is this question similar to what you get asked at work? Learn more about asking and sharing private information with your coworkers using Stack Overflow for Teams.



















          draft saved

          draft discarded
















































          Thanks for contributing an answer to Stack Overflow!


          • Please be sure to answer the question. Provide details and share your research!

          But avoid


          • Asking for help, clarification, or responding to other answers.

          • Making statements based on opinion; back them up with references or personal experience.

          To learn more, see our tips on writing great answers.




          draft saved


          draft discarded














          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55386654%2fis-there-anything-wrong-with-manually-providing-people-access-tokens-and-refresh%23new-answer', 'question_page');

          );

          Post as a guest















          Required, but never shown





















































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown

































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown







          Popular posts from this blog

          Kamusi Yaliyomo Aina za kamusi | Muundo wa kamusi | Faida za kamusi | Dhima ya picha katika kamusi | Marejeo | Tazama pia | Viungo vya nje | UrambazajiKuhusu kamusiGo-SwahiliWiki-KamusiKamusi ya Kiswahili na Kiingerezakuihariri na kuongeza habari

          Swift 4 - func physicsWorld not invoked on collision? The Next CEO of Stack OverflowHow to call Objective-C code from Swift#ifdef replacement in the Swift language@selector() in Swift?#pragma mark in Swift?Swift for loop: for index, element in array?dispatch_after - GCD in Swift?Swift Beta performance: sorting arraysSplit a String into an array in Swift?The use of Swift 3 @objc inference in Swift 4 mode is deprecated?How to optimize UITableViewCell, because my UITableView lags

          Access current req object everywhere in Node.js ExpressWhy are global variables considered bad practice? (node.js)Using req & res across functionsHow do I get the path to the current script with Node.js?What is Node.js' Connect, Express and “middleware”?Node.js w/ express error handling in callbackHow to access the GET parameters after “?” in Express?Modify Node.js req object parametersAccess “app” variable inside of ExpressJS/ConnectJS middleware?Node.js Express app - request objectAngular Http Module considered middleware?Session variables in ExpressJSAdd properties to the req object in expressjs with Typescript