82°F

Aaron Parecki

  • Articles
  • Notes
  • Photos
  • Calum Ryan | calumryan.com https://twitter.com/calum_ryan
    Session planning time at IndieWebCamp Berlin (https://calumryan.com/note/2626)
    Portland, Oregon
    Sat, May 4, 2019 10:23am +00:00 (liked on Sat, May 4, 2019 9:47am -07:00)
  • Even André Fiskvik https://twitter.com/grEvenX   •   May 3
    In the process of changing how we authorize the users in our web app and I’m wondering what route to take. Do you know about any simple proxy-like services for Oauth 2 Auth code flow (not OIDC) that can keep sessions and handle Auth for any SPA ?
    Aaron Parecki
    Plenty of server-side frameworks can do this, I'm not sure about something as a service though. Also not sure if you'd really want to go down the path of offloading that kind of thing to a different site either.
    Portland, Oregon
    1 reply
    Sat, May 4, 2019 9:46am -07:00
  • 12:28am
    Asleep
    8:30am
    Awake
    8h 02m
    Slept
    30m
    Awake for
    Portland, Oregon, USA
    Sat, May 4, 2019 8:30am -07:00
  • Aaron Parecki
    Contributions from: Bosnia and Herzegovina, Germany, Mexico, Netherlands, Peru, Switzerland, United States
    Sat, May 4, 2019 12:38am -07:00
  • See you at Oktane? Pinged you on gitter. timbl
    Portland, Oregon
    permalink (liked on Fri, May 3, 2019 9:46pm -07:00)
  • Beer
    Portland, Oregon, USA • 49°F
    Fri, May 3, 2019 6:51pm -07:00
  • Ride
    1.66mi
    Distance
    11:58
    Duration
    3:58pm
    Start
    4:10pm
    End
    Portland, Oregon • 49°F
    Fri, May 3, 2019 4:10pm -07:00
  • Aaron Parecki
    at Salmon Street Springs Fountain
    Portland, Oregon • Fri, May 3, 2019 4:01pm
    45.515367 -122.673305
    Portland, OR, United States • 49°F
    1 like 15 Coins
    Fri, May 3, 2019 4:01pm -07:00
  • Ride
    0.55mi
    Distance
    5:35
    Duration
    3:49pm
    Start
    3:55pm
    End
    Portland, Oregon • 49°F
    Fri, May 3, 2019 3:55pm -07:00
  • Calum Ryan https://calumryan.com/
    Pre-IndieWebCamp Berlin Organisers meet
    Portland, Oregon • 49°F
    Fri, May 3, 2019 8:08pm +00:00 (liked on Fri, May 3, 2019 12:46pm -07:00) #Berlin
  • Aaron Parecki
    Contributions from: Bosnia and Herzegovina, Germany, Mexico, Peru, Switzerland, United States
    Fri, May 3, 2019 10:44am -07:00
  • NSN https://twitter.com/nsnusername
    Implicit flow is history.
    Portland, Oregon • 49°F
    Thu, May 2, 2019 3:29pm +00:00 (liked on Fri, May 3, 2019 8:48am -07:00)
  • 11:28pm
    Asleep
    5:56am
    Awake
    6h 28m
    Slept
    31m
    Awake for
    Portland, Oregon, USA
    Fri, May 3, 2019 5:56am -07:00
  • Lillian Karabaic https://twitter.com/anomalily
    Just found out that @juliensolomita used my suggestion in his most recent video to do a mac + cheese tasteoff and I am STOKED. Because I love nothing more than some vegan mac. https://www.youtube.com/watch?v=EBv5A7NC2eI
    Portland, Oregon • 49°F
    Fri, May 3, 2019 12:02am +00:00 (liked on Thu, May 2, 2019 8:22pm -07:00)
  • Train
    9.02mi
    Distance
    23:19
    Duration
    7:39pm
    Start
    8:02pm
    End
    Portland, Oregon • 49°F
    Thu, May 2, 2019 8:02pm -07:00
  • Plane
    647.44mi
    Distance
    96:01
    Duration
    5:48pm
    Start
    7:25pm
    End
    Portland, Oregon • 49°F
    Thu, May 2, 2019 7:25pm -07:00
  • San Jose (SJC) to Portland (PDX)
    May 2, 2019 from 6:00pm to 7:45pm (-0700)
    Alaska Flight 309
    Portland Intl in Portland
    1 mention
    permalink #okta #oauth #iiw
  • Aaron Parecki
    at Gate 27
    San Jose, California • Thu, May 2, 2019 5:20pm
    37.364881 -121.92392
    San Jose, CA, United States
    7 Coins
    Thu, May 2, 2019 5:20pm -07:00
  • alianora https://cybre.space/@nightpool   •   May 2

    @aaronpk Yep, but in that case the attacker controls the redirect uri right? how can the attacker control the redirect uri without also controlling the pkce secret?

    Aaron Parecki
    I'm trying to explain this in 200 character chunks but it clearly isn't working. I also can't find an existing page quickly that explains it better, so clearly I need to properly write it up.
    San Jose, California • 49°F
    1 reply
    Thu, May 2, 2019 4:41pm -07:00
  • Nico Kaiser https://twitter.com/nicokaiser   •   May 2
    ... assuming I can control what JS code runs on my site (which is a different problem), this should be safe, right?
    Aaron Parecki
    That's a big assumption (you don't know what browser extensions the user is using) but yes that's one way to be more confident. I wouldn't use absolute terms like "safe" though. "Less risky" maybe.
    San Jose, California • 49°F
    Thu, May 2, 2019 4:31pm -07:00
older

Hi, I'm Aaron Parecki, Director of Identity Standards at Okta, and co-founder of IndieWebCamp. I maintain oauth.net, write and consult about OAuth, and participate in the OAuth Working Group at the IETF. I also help people learn about video production and livestreaming. (detailed bio)

I've been tracking my location since 2008 and I wrote 100 songs in 100 days. I've spoken at conferences around the world about owning your data, OAuth, quantified self, and explained why R is a vowel. Read more.

  • Director of Identity Standards at Okta
  • IndieWebCamp Founder
  • OAuth WG Editor
  • OpenID Board Member

  • 🎥 YouTube Tutorials and Reviews
  • 🏠 We're building a triplex!
  • ⭐️ Life Stack
  • ⚙️ Home Automation
  • All
  • Articles
  • Bookmarks
  • Notes
  • Photos
  • Replies
  • Reviews
  • Trips
  • Videos
  • Contact
© 1999-2025 by Aaron Parecki. Powered by p3k. This site supports Webmention.
Except where otherwise noted, text content on this site is licensed under a Creative Commons Attribution 3.0 License.
IndieWebCamp Microformats Webmention W3C HTML5 Creative Commons
WeChat ID
aaronpk_tv