vendredi 19 septembre 2014

How are OAuth-tokens self-contained?


Vote count:

0




The following blog post (http://ift.tt/1gUyYFU) states about OAuth-tokens that



Scalability of Servers: The token sent to the server is self contained which holds all the user information needed for authentication, so adding more servers to your web farm is an easy task, there is no dependent on shared session stores.



How is that implemented? What data does a token contain that can be used to properly authenticate a user? Does it contain the username and the password itself, or only a hash of the password?

How is that verified with the password hash stored in the database?



asked 1 min ago







How are OAuth-tokens self-contained?

Aucun commentaire:

Enregistrer un commentaire