Davies Meyer – home
    Tech3 min read

    OAuth

    OAuth is a framework for authorising access. An application receives limited permission to use resources in another system. OAuth 2.0 alone is not a login protocol; OpenID Connect adds a layer for verifying user identity.

    OAuth explained

    A reporting tool should read data without changing advertisements. This distinction makes authorisation important: which application may perform which action on which data? A successful connection does not establish that its permissions are appropriate.

    OAuth uses access tokens. The target system must validate their permissions and restrict them to the required resources and actions. For authorisation code flows, RFC 9700 covers protections including PKCE and precisely validated redirect addresses. These are technical safeguards, not proof of an entirely secure process.

    OpenID Connect adds identity information and can support login solutions. Granting data access and confirming identity are different tasks. A permission screen also does not replace a separate assessment of whether the intended data processing is permissible.

    Implementation must cover the full lifecycle: establish the connection, explain permissions, handle denied requests and actually end access when disconnected. Automation can support recurring steps. Convenience should not become a reason to assume extra permissions.

    Examples

    Hypothetical application

    A company connects an tool to a system. It initially grants only the required read access. The team then tests a prohibited write attempt and behaviour after disconnection. This turns a green “connected” status into a demonstrably limited connection.

    Key Points

    • Distinguish authorisation from identity verification.
    • Specify permitted resources and actions.
    • Include disconnection and permission withdrawal in testing.

    Practical application

    Describe the data and actions needed before connecting systems. Then test permitted and prohibited access, including withdrawal of permissions.

    Useful measures

    Permission scope

    Compare granted permissions with documented needs.

    Failure handling

    Check understandable behaviour when access is missing or ended.

    Business correctness

    Verify complete and correct processing of transferred data.

    Common mistakes

    • Granting every permission just in case.
    • Treating OAuth as complete security or legal approval.
    • Testing only successful connection.

    Sources and context

    Frequently Asked Questions about OAuth

    No. OAuth concerns access. OpenID Connect is often added for standardised identity information; an SSO solution also requires appropriate implementation.

    Loading related terms…

    All Terms