59°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • Dan Moore https://twitter.com/mooreds   •   Aug 11
    Although if it is a first party oauth integration (where one company controls the mobile app, the APIs, and, through a legal contract the Authorization Server), this injection is less of an issue, right?
    Aaron Parecki
    This particular issue isn't really a problem if you control the app and AS, but there are other reasons not to embed the AS page in an in-app web view.
    Austin, Texas • 99°F
    Thu, Aug 11, 2022 4:44pm -05:00
    1 like 4 replies
    • Dan Moore
    • Aaron Parecki twitter.com/aaronpk
      The only time you might be able to convince me that it's acceptable is if this account is only for one app and everything is all first party. If there's only ever one app then there's effectively no OAuth and everything (including the AS) is part of the app.
      Thu, Aug 11, 2022 10:05pm +00:00 (via brid.gy)
    • Dan Moore twitter.com/mooreds
      So in your mind, no reason to ever use a webview/embedded browser? Or do I misunderstand?
      Thu, Aug 11, 2022 10:02pm +00:00 (via brid.gy)
    • Aaron Parecki twitter.com/aaronpk
      Frankly the "system browser is horrible UX" argument lost a long time ago once the OSs provided in-app browsers that share system cookies but aren't visible to the app.
      Thu, Aug 11, 2022 9:56pm +00:00 (via brid.gy)
    • Dan Moore twitter.com/mooreds
      Agreed, as outlined here: datatracker.ietf.org/doc/html/rfc82… However, many folks, esp when first party all the way through, are willing to accept the downsides for better UX (popping out to the system browser being a pretty horrible UX). Hobson's browser is real: infrequently.org/2021/07/hobson…
      Thu, Aug 11, 2022 9:55pm +00:00 (via brid.gy)
Posted in /replies using indigenous.abode.pub/ios

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • 🎥 YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • ⚙️ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv