Android Application Question

Marc Boorshtein mboorshtein at gmail.com
Wed Jan 4 12:15:04 EST 2017


>
>
>
> That's simply the OAuth version of ECP, but it's not advisable. That
> precludes any more advanced forms of authentication without ugly
> workarounds and it destroys the branding and security measures that
> organizations take to at least try to limit phishing. It also presumes
> support for that profile by the authenticating organization, and that's
> exactly the sort of coupling that using the browser avoids.
>
>
+1 you do not want to collect passwords.  its bad.  its
crossing-the-streams-bad.  it will haunt you for all your days.

Here's an article from the Gluu folks that does a good write up.  I'm not a
mobile developer myself but I did do a POC a few years back.

https://www.gluu.org/blog/webviews-are-bad-use-appauth/
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170104/b2587332/attachment.html>


More information about the users mailing list