-
Notifications
You must be signed in to change notification settings - Fork 42
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
How to validate access token after authorization is successful? #144
Comments
Thanks for building an app! What you've posted doesn't seem to be an access token. It seems this is the raw JSON from the localstorage solid-auth-client uses internally. This is not intended to be used by anything other than solid-auth-client. It sounds like you want to do is the oidc "Authorization Code Grant" flow. At the moment solid-auth-client only supports the implicit flow, but we have plans to add other flows in the future. You can learn more about the flows here: https://medium.com/@robert.broeckelmann/when-to-use-which-oauth2-grants-and-oidc-flows-ec6a5c00d864 |
Hi @jaxoncreed, thanks for your reply. At this moment, do you have any temporary approach to validate access token on my Solid App back-end before fetching current user records? |
Unfortunately, you currently need to make requests from the client. Due to the decentralized nature of Solid, the client needs to generate new tokens every time it makes a request to a new resource server. (See more about how this works here https://github.com/solid/webid-oidc-spec/blob/master/application-user-workflow.md) This is not to say that it is impossible. We are working on the required spec changes to make this possible. (You can join the spec discussion here https://github.com/solid/authentication-panel). Just that we require more spec and implementation work to make this possible. |
As title, I've built my own Solid server and Solid App.
When I enter into the Solid App, do authentication and authorization on Solid Pod server via popup window.
Then it will get the access token on the web browser local storage.
The access token is like as follows:
Then my Solid App back-end will get these access tokens via POST method.
The Solid App back-end will fetch some records then send response to web browser and the web browser will write them to the specific Pod.
My question is: is there any approach to let Solid App back-end validate the Solid Auth Access Token?
Or is it possible to use Solid Auth access token to read/write from Solid App back-end?
Thanks.
The text was updated successfully, but these errors were encountered: