Remove obsolete / insecure OAuth2 flows from this spec
Nobody has claimed this yet.
Assessment
- Difficulty
- 1/5
- Estimated time
- Under an hour
- Newbie friendliness
- 35/100
- Issue type
- Documentation
- Clarity
- Clearly specified
- Activity status
- Stale
- Domain
- authentication, documentation, security
Research direction
Open the linked “Obtaining authentication information” section and locate the two listed OAuth2 flows. Done means both obsolete flows are removed from the specification and no longer appear in that section.
Written by the indexing model from the issue text.
Description
Here, we're listing two flows: https://github.com/buildingSMART/foundation-API#221-obtaining-authentication-information
implicit_grant, which has been effectively deprecated, or at least it's usage is heavily discouragedresource_owner_password_credentials_grant, which never really was considered secure in scenarios where you did not control all services involved
This was brought up in the meeting today, and we should just remove it from the spec completely.
- Dominant language
- No language data
- Stars
- 39
- Forks
- 9
- PR merge metrics
- No merged PRs in 30d
Getting set up
This project ships no dev container, Dockerfile or contributing guide, so setting up is up to you: start from its README, and see our first-contribution guide for the general steps.
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from buildingSMART/foundation-API
-
Difficulty 4/5 3-5 days Newbie friendliness 30/100
-
Difficulty 4/5 3-5 days Newbie friendliness 38/100
buildingSMART/foundation-API#42 · 2 comments ·
-
Difficulty 3/5 1-2 days Newbie friendliness 42/100
buildingSMART/foundation-API#41 · 1 comment ·
-
Difficulty 4/5 3-5 days Newbie friendliness 25/100
buildingSMART/foundation-API#39 · 1 comment · 2 reactions ·
-
Difficulty 5/5 Over a week Newbie friendliness 25/100
buildingSMART/foundation-API#26 · 3 comments ·
All issues in buildingSMART/foundation-API
Similar issues
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Maintainers usually reply within 1 day
-
Mend: dependency security vulnerability untriaged
Difficulty 2/5 1-3 hours Newbie friendliness 72/100
opensearch-project/OpenSearch-Dashboards#12878 ·
Maintainers usually reply within 1 day
-
ubreakifix.comOpenUnsorted
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
AdguardTeam/AdguardFilters#243331 ·
Maintainers usually reply within 1 day
-
good first issue hacktoberfest help wanted
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
libredb/libredb-studio#1291 · 1 comment ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 76/100
elsa-workflows/elsa-core#8593 ·
Maintainers usually reply within 1 day