Cihaz Yetkilendirme İzni
Akıllı televizyonlar, konsollar ve CLI araçları gibi giriş kapasitesi sınırlı cihazların ikincil bir cihaz üzerinden belirteç almasını sağlayan OAuth2 Cihaz Yetkilendirme İznini (RFC 8628) öğrenin.
Cihaz Yetkilendirme İzni, CoddyKit'te ücretsiz bir OAuth2 & OpenID Connect Deep Dive dersidir. Bu, 4 dersinin 4. dersidir. Aşağıdan dersin tamamını ücretsiz okuyabilir, sonra tarayıcıda yerleşik kod editörü ve 7/24 yapay zeka koçu ile uygulamalı olarak pratik yapabilirsin. Bu, OAuth2 & OpenID Connect Deep Dive öğrenme yolunun bir parçasıdır ve ilerlemeniz web ve CoddyKit uygulaması arasında senkronize olur. OAuth2 & OpenID Connect Deep Dive kursu toplamda 4 dersten oluşur.
Bu dersin bazı bölümleri henüz çevrilmemiş olup İngilizce olarak gösterilmektedir.
Why a Device Grant?
Some clients have no browser or only a limited keypad: smart TVs, media consoles, printers, and CLI tools. The classic Authorization Code Flow assumes a rich browser for the user-agent redirect, which these devices cannot provide.
The Device Authorization Grant (RFC 8628) solves this by letting the user complete authorization on a second device (phone or laptop) while the constrained device polls for the result.
The Two Endpoints
The flow introduces a new device authorization endpoint alongside the standard token endpoint.
/device_authorization— the device requests codes here./token— the device polls here with grant typeurn:ietf:params:oauth:grant-type:device_code.
No redirect URI is involved at all.
Step 1: Requesting Device Codes
The device makes a POST to the device authorization endpoint with its client_id and desired scope.
POST /device_authorization HTTP/1.1
Host: auth.example.com
Content-Type: application/x-www-form-urlencoded
client_id=tv-app-123&scope=profile emailStep 2: The Response
The server returns a device_code (used by the machine), a user_code (typed by the human), a verification_uri, an expires_in, and an interval for polling.
{
"device_code": "GmRhmhcxhwAzkoEqiMEg",
"user_code": "WDJB-MJHT",
"verification_uri": "https://example.com/device",
"expires_in": 900,
"interval": 5
}Step 3: User Instructions
The device displays a short message: Go to example.com/device and enter code WDJB-MJHT.
A verification_uri_complete may also be returned, embedding the code so a QR code can carry the whole link.
Step 4: User Authorizes
On their phone or laptop, the user opens the verification URI, logs in, enters the user_code, and approves the requested scopes. This happens in a full browser, so MFA and rich consent screens all work normally.
Step 5: Device Polls the Token Endpoint
Meanwhile the device polls the token endpoint at the given interval, sending the device_code.
POST /token HTTP/1.1
Host: auth.example.com
Content-Type: application/x-www-form-urlencoded
grant_type=urn:ietf:params:oauth:grant-type:device_code
&device_code=GmRhmhcxhwAzkoEqiMEg
&client_id=tv-app-123Polling Responses
Until the user finishes, the server returns errors that tell the device how to behave:
authorization_pending— keep polling, user has not approved yet.slow_down— increase the interval by 5 seconds.access_denied— user rejected; stop.expired_token— codes expired; restart.
Step 6: Success
Once the user approves, the next poll returns a normal token response with an access_token (and optionally a refresh_token), exactly like other grants.
{
"access_token": "eyJhbGciOi...",
"token_type": "Bearer",
"expires_in": 3600,
"refresh_token": "8xLOxBtZp8"
}A Simple Poll Loop
A pseudo-implementation of the polling logic, respecting slow_down:
let interval = 5;
while (true) {
await sleep(interval * 1000);
const res = await pollToken(deviceCode);
if (res.access_token) return res;
if (res.error === 'slow_down') interval += 5;
else if (res.error === 'authorization_pending') continue;
else throw new Error(res.error);
}Security Considerations
Keep user_codes short but high-entropy to resist brute force, and rate-limit the verification page. Because there is no redirect, phishing risk shifts to the verification URI — always show the user exactly which app and scopes they are approving.
Quick Check
Test your understanding of the device grant.
Recap
The Device Authorization Grant lets browserless devices authenticate users via a second device.
- Device gets a
device_code+user_codefrom the device endpoint. - User approves on a phone/laptop at the verification URI.
- Device polls the token endpoint, handling
authorization_pendingandslow_down. - On approval it receives normal access and refresh tokens.
Sıkça Sorulan Sorular
“Cihaz Yetkilendirme İzni” dersi ücretsiz mi?
Evet — “Cihaz Yetkilendirme İzni” dersin tüm metni burada web'de ücretsiz olarak okunabilir. Etkileşimli olarak pratik yapmak (yerleşik kod editörü ve 7/24 yapay zeka koçu) ve OAuth2 & OpenID Connect Deep Dive kursunun geri kalanını açmak için CoddyKit PRO'ya yükselt. OAuth2 & OpenID Connect Deep Dive kursu toplamda 4 dersten oluşur.
“Cihaz Yetkilendirme İzni” dersinde ne öğreneceğim?
Akıllı televizyonlar, konsollar ve CLI araçları gibi giriş kapasitesi sınırlı cihazların ikincil bir cihaz üzerinden belirteç almasını sağlayan OAuth2 Cihaz Yetkilendirme İznini (RFC 8628) öğrenin. OAuth2 & OpenID Connect Deep Dive ile uygulamalı kodu tarayıcıda doğrudan çalıştırarak pratik yaparsın ve 7/24 yapay zeka koçu dersi çalışırken sorularını yanıtlar.
OAuth2 & OpenID Connect Deep Dive öğrenmeye başlamak için deneyim gerekli mi?
Önceden deneyim gerekmez. CoddyKit'te OAuth2 & OpenID Connect Deep Dive, başlangıçtan ileri seviyeye kadar yapılandırıldığı için buradan başlayabilir veya başından başlayıp kendi hızında ilerleme yapabilirsin. Bu, 4 dersinin 4. dersidir.
“Cihaz Yetkilendirme İzni” dersi ne kadar sürer?
Çoğu CoddyKit dersi yaklaşık 5–10 dakika sürer. Her biri kısa ve etkileşimli olduğu için sabit ilerleme yaparsın ve web ile uygulama arasında tam olarak bıraktığın yerden devam edebilirsin.
Bu OAuth2 & OpenID Connect Deep Dive dersinde kod yazıp çalıştırabilir miyim?
Evet. Her OAuth2 & OpenID Connect Deep Dive dersi yerleşik bir kod editörü içerir, bu sayede tarayıcıda gerçek kod yazıp çalıştırabilir ve anlık yapay zeka geri bildirimi alırsın — yerel kurulum gerekli değildir.
Bu kursun tüm dersleri
- Yetkilendirme Kodu Akışı
- İstemci Kimlik Bilgileri Akışı
- Örtük Akış ve Kullanımdan Kaldırılması
- Cihaz Yetkilendirme İzni