In the previous video, I explained that OAuth’s Resource Owner Password Credentials Grant must not be used except for backward compatibility. I then received a question asking, “Since it is described in RFC6749, isn’t it strange to say that it must not be used?” So, while answering that question, I explained what it means to use it for “backward compatibility.” I hope you enjoy it.

Watch this video on YouTube.
Playing the video connects to YouTube.

 

Related posts

OAuth PKCE Published as RFC7636

OAuth PKCE (pronounced “pixy”), for which John Bradley (Ping), Naveen Agarwal (Google), and I are credited as co-authors, has been published as [RFC 7636]. It was…

OAuth · 2015-09-18