Empresas
Empregos
  • Sobre nós
  • Soluções
    • Publicação de vagas
      Publique sua vaga e receba candidatos qualificados em 48h.
    • Avaliações de candidatos
      Mais de 500 testes técnicos e psicológicos, mais anti-fraude.
    • Headhunting
      Busca executiva personalizada do início ao fim.
    • Folha de Pagamento + EOR
      Dispersão de folha e EOR em mais de 15 países da LATAM.
  • Preços
  • Empregos

0

282
Visualizações
How to know which user completed web/server side OAuth 2.0 flow initiated by a client such as a Chrome Extension?

I'm working on a Chrome Extension, and it's using personal access tokens (Laravel Sanctum) to authenticate the extension/user with the backend/server API. So basically when sending requests to the endpoints from the extension I'm including the Authorization header with the Bearer token.

I want to add some third party integrations which will use OAuth 2.0 for authentication, and I want those integrations to be connected with the user on the backend (server) and not the extension itself. Basically, my server (API) will be a proxy between the integration API and the extension.

In the extension, when a user tries to connect an integration, a window opens and my server redirects the user to appropriate integration authorization URL (with my client id, scope, redirect uri, etc.) where the user can then authorize my app. After that's done the user is redirected to the provided redirect_uri (my domain) with the authorization code.

What is a smart and secure way to know which user (my user, not integration's) connected the integration, considering that my user identification (including the token for communicating with my API) is stored locally on the extension, and is not immediately available in the OAuth flow.

My idea is, when opening the OAuth window, pass the user data to my server (GET or POST), store a cookie, and then redirect to the integration's authorization URL, and when the user authorizes my app and gets redirected to the redirect_uri, my user data will be available in the cookie so that I can assign the authorization code to the appropriate user. Is this a good way to do it?

about 4 years ago · Juan Pablo Isaza
Responde à pergunta
Encontrar trabalhos remotos

Descubra a nova forma de encontrar um emprego!

melhores empregos
Principais categorias de trabalho
Empresas
Postar vaga Preços Comercial
Jurídico
Termos e Condições Política de privacidade
© 2026 PeakU Inc. All Rights Reserved.
Andres GPT
Recomende algumas ofertas para mim
Preciso de ajuda