Chapter 12. OAuth for Native Applications
Native applications are platform-specific executable programs that you build for and run on a dedicated operating system. The main types are desktop applications and mobile applications. In most cases, users operate those applications and they interact with APIs to present secured data to the user. To call APIs, platform-specific applications run a code flow with Proof Key for Code Exchange (PKCE) (RFC 7636) as we explain in Chapter 2, to retrieve an access token that identifies the user. The client sends the access token to APIs, which use the token’s claims to implement business authorization. The client continues to call APIs until the user closes the application or the user’s authenticated session expires.
This chapter explains the options you have when you use OAuth to secure platform-specific applications. We first provide a refresher on the code flow, where the client sends an authorization request using the system browser. We then explain how to implement OAuth for platform-specific applications in the standard ways, which requires special types of redirect URIs that use features of the operating system. Next, we describe methods with which you can harden the security of the OAuth implementation and mitigate threats that exist in the various environments. To complete the theory, we explain how OAuth could use browserless flows to authenticate users with device features that the browser cannot access. To finish up, we provide practical ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access