Is there anything wrong with manually providing people access tokens and refresh tokens so they don't have to do the OAuth2 dance themselves?How should I ethically approach user password storage for later plaintext retrieval?Why Does OAuth v2 Have Both Access and Refresh Tokens?What is the purpose of the implicit grant authorization type in OAuth 2?Why is there an “Authorization Code” flow in OAuth2 when “Implicit” flow works so well?What is the difference between the OAuth Authorization Code and Implicit workflows? When to use each one?How should I store and revoke OAuth2 authorizations and/or refresh tokens?OAuth2 - unnecessary complexity with refresh tokenClient secret + refreshing the access token in spring oauth2OAuth2 refresh token utilityOAuth2 purpose of refresh token with authorization code

Group riding etiquette

Heat output from a 200W electric radiator?

Are there any to-scale diagrams of the TRAPPIST-1 system?

Find most "academic" implementation of doubly linked list

Normalized Malbolge to Malbolge translator

Looking for a plural noun related to ‘fulcrum’ or ‘pivot’ that denotes multiple things as crucial to success

Adding and Multiplying Elements of a list together

If I said I had $100 when asked, but I actually had $200, would I be lying by omission?

Notice period 60 days but I need to join in 45 days

Is there an in-universe explanation given to the senior Imperial Navy Officers as to why Darth Vader serves Emperor Palpatine?

Why doesn't Starship have four landing legs?

Why is 3/4 a simple meter while 6/8 is a compound meter?

Defending Castle from Zombies

Why does a sticker slowly peel off, but if it is pulled quickly it tears?

Why does Sauron not permit his followers to use his name?

Number of Fingers for a Math Oriented Race

Is it unusual for a math department not to have a mail/web server?

web scraping images

What will be the immediate action by the pilot and ATC if any plane blocks the runway while landing?

Why does AM radio react to IR remote?

How to handle inventory and story of a player leaving

Why didn't Doc believe Marty was from the future?

Can I lend a small amount of my own money to a bank at the federal funds rate?

How could a self contained organic body propel itself in space



Is there anything wrong with manually providing people access tokens and refresh tokens so they don't have to do the OAuth2 dance themselves?


How should I ethically approach user password storage for later plaintext retrieval?Why Does OAuth v2 Have Both Access and Refresh Tokens?What is the purpose of the implicit grant authorization type in OAuth 2?Why is there an “Authorization Code” flow in OAuth2 when “Implicit” flow works so well?What is the difference between the OAuth Authorization Code and Implicit workflows? When to use each one?How should I store and revoke OAuth2 authorizations and/or refresh tokens?OAuth2 - unnecessary complexity with refresh tokenClient secret + refreshing the access token in spring oauth2OAuth2 refresh token utilityOAuth2 purpose of refresh token with authorization code






.everyoneloves__top-leaderboard:empty,.everyoneloves__mid-leaderboard:empty,.everyoneloves__bot-mid-leaderboard:empty margin-bottom:0;








0















This seems like an odd question, but something I've been pondering.



I have an API that I'd like people to use, but the people using it require a lot of hand holding through the OAuth2 process to get an access token.



Instead of throwing OAuth2 authorization code grant requirements at my users, what I'd like to do is provide them with a web user interface, where they can copy down revocable access tokens and refresh tokens.



Once people have their tokens, they can plug them into their client application and they're away. If tokens need to be revoked, they can be revoked through my web user interface.



For server to server connections, this seems 'safer'?? than OAuth2 password grant because by forcing people to log into a website to get tokens, people are always required to provide a username and password directly to my system. There is less chance of another intermediary system caching credential information in between the client system and mine.



Is my thinking solid on this or is it a little suspect? Part of me feels wrong for allowing users to skip the Oauth2 authorization code flow entirely.










share|improve this question






























    0















    This seems like an odd question, but something I've been pondering.



    I have an API that I'd like people to use, but the people using it require a lot of hand holding through the OAuth2 process to get an access token.



    Instead of throwing OAuth2 authorization code grant requirements at my users, what I'd like to do is provide them with a web user interface, where they can copy down revocable access tokens and refresh tokens.



    Once people have their tokens, they can plug them into their client application and they're away. If tokens need to be revoked, they can be revoked through my web user interface.



    For server to server connections, this seems 'safer'?? than OAuth2 password grant because by forcing people to log into a website to get tokens, people are always required to provide a username and password directly to my system. There is less chance of another intermediary system caching credential information in between the client system and mine.



    Is my thinking solid on this or is it a little suspect? Part of me feels wrong for allowing users to skip the Oauth2 authorization code flow entirely.










    share|improve this question


























      0












      0








      0








      This seems like an odd question, but something I've been pondering.



      I have an API that I'd like people to use, but the people using it require a lot of hand holding through the OAuth2 process to get an access token.



      Instead of throwing OAuth2 authorization code grant requirements at my users, what I'd like to do is provide them with a web user interface, where they can copy down revocable access tokens and refresh tokens.



      Once people have their tokens, they can plug them into their client application and they're away. If tokens need to be revoked, they can be revoked through my web user interface.



      For server to server connections, this seems 'safer'?? than OAuth2 password grant because by forcing people to log into a website to get tokens, people are always required to provide a username and password directly to my system. There is less chance of another intermediary system caching credential information in between the client system and mine.



      Is my thinking solid on this or is it a little suspect? Part of me feels wrong for allowing users to skip the Oauth2 authorization code flow entirely.










      share|improve this question














      This seems like an odd question, but something I've been pondering.



      I have an API that I'd like people to use, but the people using it require a lot of hand holding through the OAuth2 process to get an access token.



      Instead of throwing OAuth2 authorization code grant requirements at my users, what I'd like to do is provide them with a web user interface, where they can copy down revocable access tokens and refresh tokens.



      Once people have their tokens, they can plug them into their client application and they're away. If tokens need to be revoked, they can be revoked through my web user interface.



      For server to server connections, this seems 'safer'?? than OAuth2 password grant because by forcing people to log into a website to get tokens, people are always required to provide a username and password directly to my system. There is less chance of another intermediary system caching credential information in between the client system and mine.



      Is my thinking solid on this or is it a little suspect? Part of me feels wrong for allowing users to skip the Oauth2 authorization code flow entirely.







      security oauth-2.0






      share|improve this question













      share|improve this question











      share|improve this question




      share|improve this question










      asked Mar 27 at 21:22









      John DeverallJohn Deverall

      1,92217 silver badges26 bronze badges




      1,92217 silver badges26 bronze badges

























          0






          active

          oldest

          votes










          Your Answer






          StackExchange.ifUsing("editor", function ()
          StackExchange.using("externalEditor", function ()
          StackExchange.using("snippets", function ()
          StackExchange.snippets.init();
          );
          );
          , "code-snippets");

          StackExchange.ready(function()
          var channelOptions =
          tags: "".split(" "),
          id: "1"
          ;
          initTagRenderer("".split(" "), "".split(" "), channelOptions);

          StackExchange.using("externalEditor", function()
          // Have to fire editor after snippets, if snippets enabled
          if (StackExchange.settings.snippets.snippetsEnabled)
          StackExchange.using("snippets", function()
          createEditor();
          );

          else
          createEditor();

          );

          function createEditor()
          StackExchange.prepareEditor(
          heartbeatType: 'answer',
          autoActivateHeartbeat: false,
          convertImagesToLinks: true,
          noModals: true,
          showLowRepImageUploadWarning: true,
          reputationToPostImages: 10,
          bindNavPrevention: true,
          postfix: "",
          imageUploader:
          brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
          contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
          allowUrls: true
          ,
          onDemand: true,
          discardSelector: ".discard-answer"
          ,immediatelyShowMarkdownHelp:true
          );



          );













          draft saved

          draft discarded


















          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55386654%2fis-there-anything-wrong-with-manually-providing-people-access-tokens-and-refresh%23new-answer', 'question_page');

          );

          Post as a guest















          Required, but never shown

























          0






          active

          oldest

          votes








          0






          active

          oldest

          votes









          active

          oldest

          votes






          active

          oldest

          votes




          Is this question similar to what you get asked at work? Learn more about asking and sharing private information with your coworkers using Stack Overflow for Teams.







          Is this question similar to what you get asked at work? Learn more about asking and sharing private information with your coworkers using Stack Overflow for Teams.



















          draft saved

          draft discarded
















































          Thanks for contributing an answer to Stack Overflow!


          • Please be sure to answer the question. Provide details and share your research!

          But avoid


          • Asking for help, clarification, or responding to other answers.

          • Making statements based on opinion; back them up with references or personal experience.

          To learn more, see our tips on writing great answers.




          draft saved


          draft discarded














          StackExchange.ready(
          function ()
          StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fstackoverflow.com%2fquestions%2f55386654%2fis-there-anything-wrong-with-manually-providing-people-access-tokens-and-refresh%23new-answer', 'question_page');

          );

          Post as a guest















          Required, but never shown





















































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown

































          Required, but never shown














          Required, but never shown












          Required, but never shown







          Required, but never shown







          Popular posts from this blog

          Kamusi Yaliyomo Aina za kamusi | Muundo wa kamusi | Faida za kamusi | Dhima ya picha katika kamusi | Marejeo | Tazama pia | Viungo vya nje | UrambazajiKuhusu kamusiGo-SwahiliWiki-KamusiKamusi ya Kiswahili na Kiingerezakuihariri na kuongeza habari

          SQL error code 1064 with creating Laravel foreign keysForeign key constraints: When to use ON UPDATE and ON DELETEDropping column with foreign key Laravel error: General error: 1025 Error on renameLaravel SQL Can't create tableLaravel Migration foreign key errorLaravel php artisan migrate:refresh giving a syntax errorSQLSTATE[42S01]: Base table or view already exists or Base table or view already exists: 1050 Tableerror in migrating laravel file to xampp serverSyntax error or access violation: 1064:syntax to use near 'unsigned not null, modelName varchar(191) not null, title varchar(191) not nLaravel cannot create new table field in mysqlLaravel 5.7:Last migration creates table but is not registered in the migration table

          은진 송씨 목차 역사 본관 분파 인물 조선 왕실과의 인척 관계 집성촌 항렬자 인구 같이 보기 각주 둘러보기 메뉴은진 송씨세종실록 149권, 지리지 충청도 공주목 은진현