OAuth2 และ Authorization Server
OAuth2 และ Authorization Server, flow (authorization code, client credentials), resource server, scopes
1OAuth2 คืออะไร?
OAuth2 คืออะไร?
คำตอบ
OAuth2 เป็นโปรโตคอลการอนุญาต (authorization) ที่ช่วยให้แอปพลิเคชันของบุคคลที่สามได้รับสิทธิ์เข้าถึงบริการ HTTP แบบจำกัดในนามของผู้ใช้ โดยไม่ต้องเปิดเผย credentials ของผู้ใช้ มันทำงานผ่าน access token แทนที่จะใช้รหัสผ่าน OAuth2 ถูกใช้อย่างแพร่หลายสำหรับการยืนยันตัวตนแบบมอบหมาย (เข้าสู่ระบบผ่าน Google, GitHub ฯลฯ) และ REST API ที่ปลอดภัย
2OAuth2 flow ใดปลอดภัยที่สุดสำหรับเว็บแอปพลิเคชัน?
OAuth2 flow ใดปลอดภัยที่สุดสำหรับเว็บแอปพลิเคชัน?
คำตอบ
Authorization Code flow เป็น flow ที่ปลอดภัยที่สุดเพราะ access token ไม่เคยถูกเปิดเผยต่อเบราว์เซอร์ แอปพลิเคชัน backend จะแลกเปลี่ยน authorization code ชั่วคราวเป็น access token ผ่านช่องทางที่ปลอดภัย (backend-to-backend) ด้วย PKCE (Proof Key for Code Exchange) flow นี้จะปลอดภัยยิ่งขึ้นต่อการโจมตีแบบ interception
3ควรใช้ Client Credentials flow ในกรณีใด?
ควรใช้ Client Credentials flow ในกรณีใด?
คำตอบ
Client Credentials flow ออกแบบมาสำหรับการสื่อสารแบบ machine-to-machine (service-to-service) โดยไม่มีบริบทของผู้ใช้ แอปพลิเคชัน client จะยืนยันตัวตนโดยตรงด้วย credentials ของตนเอง (client_id และ client_secret) เพื่อรับ access token ใช้สำหรับ batch job, microservice หรือ backend API ที่ทำงานในนามของตนเอง
PKCE (Proof Key for Code Exchange) ใน OAuth2 คืออะไร?
ทำไม Implicit flow จึงถูกเลิกใช้ (deprecated) ใน OAuth2?
+17 คำถามสัมภาษณ์
หัวข้อสัมภาษณ์ Spring Boot อื่นๆ
Spring Core - IoC & DI
Spring Boot Auto-Configuration
Spring Boot Starters
Application Properties & YAML
การทำ Logging ด้วย SLF4J และ Logback
Spring Boot DevTools
Spring MVC Basics
Spring REST Controllers
Request & Response Handling
การจัดการข้อยกเว้น
Bean Validation
พื้นฐาน Spring Data JPA
เอนทิตี JPA และความสัมพันธ์
การสืบค้น JPA
Spring Data Repositories
พื้นฐาน Spring Security
Spring Boot Actuator
การทดสอบหน่วยด้วย JUnit และ Mockito
การทดสอบ Spring Boot
Profiles และ Environment
RestTemplate และ WebClient
Async และ Scheduling
Caching ด้วย Spring
Spring WebFlux (Reactive)
ทรานแซกชัน Spring
การยืนยันตัวตนและการให้สิทธิ์ขั้นสูง
JWT และความปลอดภัยแบบ Stateless
Spring Boot และ Docker
Microservices ด้วย Spring
Spring Cloud Config
การเพิ่มประสิทธิภาพการทำงาน
GraalVM Native Images
เชี่ยวชาญ Spring Boot สำหรับการสัมภาษณ์ครั้งถัดไป
เข้าถึงคำถามทั้งหมด flashcards แบบทดสอบเทคนิค แบบฝึกหัด code review และตัวจำลองสัมภาษณ์
เริ่มใช้ฟรี