Difference between revisions of "Authorization Request"
From MgmtWiki
(→Context) |
(→Full Title or Meme) |
||
Line 1: | Line 1: | ||
==Full Title or Meme== | ==Full Title or Meme== | ||
− | Simply put the [[Authorization Request]] is sent from one service to another to | + | Simply put the [[Authorization Request]] is sent from one service to another to request for access to a protected resource. |
==Context== | ==Context== |
Revision as of 09:10, 25 March 2021
Full Title or Meme
Simply put the Authorization Request is sent from one service to another to request for access to a protected resource.
Context
- In the context of Identity Management the Authorization Request is sent by the Relying Party (RP) to an Authorization Endpoint to acquire sufficient information about the user to establish an authenticated communication session.
- The Authorization Request was formally described in OAuth 2.0 to be a collection of query parameters to be added to a URL for exmaple /Auhtorize?parm1=value1& other clam ins as appropriate.
Problems
Solutions
- A series of RFCs on extensions to the Authorization Request were developed during 2020. These are well describe in a presentation for Auth0.