Showing posts with label oidc. Show all posts
Showing posts with label oidc. Show all posts

Single-Page Application

 This was a new term for me as I started putting together my most recent study guide. SPA, which stands for Single-Page Application.  While it sounds like a simple website, an SPA represents a fundamental shift in how web applications function, bringing unique challenges to the world of information security.  Understanding SPAs is critical because they are the primary reason tools like PKCE and OIDC became industry standards.

Single Page Application

Adding Identity to the Authorization Layer

 In the journey through information security, you will frequently encounter OAuth 2.0. While OAuth is excellent at authorization, it was never actually designed for authentication. To solve this, OIDC, or OpenID Connect, was created.  Think of it this way: OAuth 2.0 is the key to a hotel room, while OIDC is the ID card that proves you are the person who booked it.

oidc-openid-connect