OAuth2 & OpenID Connect Deep Dive · Leçon

Rôles et terminologie d’OAuth2

Comprenez les acteurs principaux — propriétaire de la ressource, client, serveur d’autorisation et serveur de ressources — ainsi que leurs interactions.

Leçon 2 sur 411 étapes

Rôles et terminologie d’OAuth2 est une leçon OAuth2 & OpenID Connect Deep Dive gratuite sur CoddyKit. Ceci est la leçon 2 sur 4. Tu peux lire la leçon complète ci-dessous gratuitement — puis la pratiquer en direct dans le navigateur avec un éditeur de code intégré et un tuteur IA 24/7. Elle fait partie du parcours d'apprentissage OAuth2 & OpenID Connect Deep Dive, et ta progression se synchronise sur le web et l'application CoddyKit. Le cours OAuth2 & OpenID Connect Deep Dive comprend 4 leçons au total.

Certaines parties de cette leçon n'ont pas encore été traduites et s'affichent en anglais.

Intro to OAuth2 Roles

Welcome! OAuth2 involves several key players working together. Understanding each role is crucial to grasp how it secures access to your data without sharing your password.

Let's meet the main characters in the OAuth2 story!

The Resource Owner: You!

The Resource Owner is typically you, the end-user. You own the protected resources (like your photos, contacts, or profile information) stored on a service.

  • You grant permission to applications to access your resources.
  • You never directly share your password with the application.

The Client Application

The Client Application (or just "Client") is the application that wants to access your protected resources. This could be a mobile app, a web application, or even another server-side application.

  • It needs your permission to act on your behalf.
  • It doesn't store your credentials.

The Authorization Server

The Authorization Server (AuthZ Server) is the core of OAuth2. It's responsible for:

  • Authenticating the Resource Owner (you).
  • Obtaining your consent for the Client.
  • Issuing access tokens to the Client.

Think of it as the trusted authority that manages permissions.

The Resource Server

The Resource Server is where your protected resources actually live. This is the API server that holds your photos, emails, or other data.

  • It receives requests from the Client.
  • It validates the access token presented by the Client.
  • If the token is valid, it grants access to the requested resources.

Roles in Action: Simple Flow

Here's a simplified look at how these roles interact:

  1. The Client asks the Resource Owner for permission.
  2. The Resource Owner interacts with the Authorization Server to grant consent.
  3. The Authorization Server gives an access token to the Client.
  4. The Client uses this token to request resources from the Resource Server.

Example: Photo Printing App

Let's say you use a "Print My Photos" app (Client) to print pictures from your Google Photos (Resource Server).

Instead of giving the app your Google password, Google (Authorization Server) asks you if the app can access your photos. You say "Yes," Google gives the app a special token, and the app uses that token to get your photos.

Access Tokens: The Keys

When the Authorization Server issues an access token, it's like giving the Client a temporary, specific key.

  • This key only unlocks certain resources (defined by "scopes").
  • It has a limited lifespan.
  • If lost, it doesn't expose your main password.

We'll cover tokens in more detail later!

The Chain of Trust

OAuth2 builds a chain of trust:

  • The Resource Owner trusts the Authorization Server to handle their consent.
  • The Client trusts the Authorization Server to issue valid tokens.
  • The Resource Server trusts the Authorization Server to verify tokens it receives.

This allows secure delegation without password sharing.

Quick Check: Identify Role

Consider a mobile banking app that wants to display your transaction history from your bank's API.

Which OAuth2 role represents the mobile banking app?

Recap: The Core Players

In this lesson, we identified the four fundamental roles in OAuth2:

  • Resource Owner: The user who owns the data.
  • Client Application: The app requesting access.
  • Authorization Server: Manages user consent and issues tokens.
  • Resource Server: Hosts the protected data and validates tokens.

Understanding these roles is vital for grasping OAuth2's secure delegation model. Next, we'll look at the different ways these roles interact through "grant types"!

Gratuit pour commencer

Apprends OAuth2 & OpenID Connect Deep Dive avec un tuteur IA — gratuit

Écris et exécute du vrai code dans ton navigateur, obtiens de l'aide instantanée d'un tuteur IA disponible 24h/24, et reprends là où tu t'es arrêté sur le web ou dans l'app.

Cours
12
Leçons
48

Questions Fréquemment Posées

La leçon « Rôles et terminologie d’OAuth2 » est-elle gratuite ?

Oui — le texte complet de « Rôles et terminologie d’OAuth2 » est gratuit à lire ici sur le web. Pour la pratiquer de manière interactive (un éditeur de code intégré et un tuteur IA 24/7) et déverrouiller le reste du cours OAuth2 & OpenID Connect Deep Dive, passe à CoddyKit PRO. Le cours OAuth2 & OpenID Connect Deep Dive comprend 4 leçons au total.

Qu'est-ce que j'apprendrai dans « Rôles et terminologie d’OAuth2 » ?

Comprenez les acteurs principaux — propriétaire de la ressource, client, serveur d’autorisation et serveur de ressources — ainsi que leurs interactions. Tu pratiques OAuth2 & OpenID Connect Deep Dive avec du code pratique que tu exécutes directement dans le navigateur, et un tuteur IA 24/7 répond à tes questions au fur et à mesure que tu avances dans la leçon.

Dois-je avoir de l'expérience pour commencer OAuth2 & OpenID Connect Deep Dive ?

Aucune expérience préalable n'est requise. OAuth2 & OpenID Connect Deep Dive sur CoddyKit est structuré pour les débutants jusqu'aux apprenants avancés, donc tu peux commencer ici ou depuis le début et avancer à ton rythme. Ceci est la leçon 2 sur 4.

Combien de temps prend la leçon « Rôles et terminologie d’OAuth2 » ?

La plupart des leçons CoddyKit prennent environ 5–10 minutes. Chacune est courte et interactive, tu progresses régulièrement et tu repiques exactement où tu t'es arrêté sur le web et l'app.

Peux-tu écrire et exécuter du code dans cette leçon OAuth2 & OpenID Connect Deep Dive ?

Oui. Chaque leçon OAuth2 & OpenID Connect Deep Dive inclut un éditeur de code intégré, tu écris et exécutes du vrai code directement dans ton navigateur et tu reçois des retours IA instantanés — aucune configuration locale requise.

Toutes les leçons de ce cours

  1. OAuth2 : le protocole de délégation
  2. Rôles et terminologie d’OAuth2
  3. Vue d’ensemble des types d’octroi
  4. Jetons d’accès, jetons d’actualisation et portées
← Retour à OAuth2 & OpenID Connect Deep Dive