<div dir="ltr"><div class="gmail_extra"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><span class="gmail-"><br>
<br>
</span>That's simply the OAuth version of ECP, but it's not advisable. That precludes any more advanced forms of authentication without ugly workarounds and it destroys the branding and security measures that organizations take to at least try to limit phishing. It also presumes support for that profile by the authenticating organization, and that's exactly the sort of coupling that using the browser avoids.<br>
<span class="gmail-HOEnZb"><font color="#888888"><br></font></span></blockquote><div><br></div><div>+1 you do not want to collect passwords. its bad. its crossing-the-streams-bad. it will haunt you for all your days.</div><div><br></div><div>Here's an article from the Gluu folks that does a good write up. I'm not a mobile developer myself but I did do a POC a few years back. </div><div><br></div><div><a href="https://www.gluu.org/blog/webviews-are-bad-use-appauth/">https://www.gluu.org/blog/webviews-are-bad-use-appauth/</a><br></div></div></div></div>