Login to Epicor Kinetic with ANY OpenID Connect Provider (On-Prem) Okta, Auth0, Entra, Facebook🤪: (Ok maybe not facebook)

oauth.net / oauth.com by Aaron Parecki are a good starting point

Nate Berbettini’s talk on OAuth in Plain English is awesome

And if you are super awesome like me you could just RAW read the RFC’s because there’s nothing more entretaining not at all boring and or dry than reading RFC’s

pleasure GIF

RFC 6749 (OAuth 2.0 core)
RFC 6750 (Bearer tokens)
RFC 7636 (PKCE)
RFC 7519 (JWT) ← This one is so cool… Non encrypted JWTs are ā€œsome how magicallyā€ still cryptographically secure… MATHS is awesome
RFC 7517 (JWK)
RFC 8414
RFC 9700

rachel mcadams season GIF

NOTE: Desperation, exhasperation and all other ations may occur upon reading these above, think of it as exposure therapy. Unrelated someone should do a dramatic reading of these it may get some traction, Audible Full Cast Edition JWT RFC? #SignMeUp

Thank you for the therapy :laughing:

the csp thing is surprising I thought the policy was very permissive. :man_shrugging:

Not in this case it threw down right fit

There are also some good NDC Talks as well, some basic, some blow past me…

BTW, Duende Software is the organization who took Identity Server (like Jose said, the basis of IdP) into a for-pay product.

Thanks Mark

Not happy about that. They also gave a big :fu:t2: to their partners of many years. And told customers of their partners - start paying.

Understood, but then again, working for free is a bad business model for a security firm. I agree, the way they did it sucked. Others, like Jimmy Bogard did a better job.

I agree free isn’t a viable long-term model. They sold to a Capital Investment company and magically, everything is now pay to play. Typical model.

Now you tell me!

Mascot Flipping GIF by MLB