Integrate oauth login (openid connect) #5
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Motivation
I want to make users able to login and signup using their google account.
Oauth login is common in many websites, it's really handy and makes it the authentication flow easier for users.
To be precise, oauth is for authorization. Here I'm using openid connect, that is built on top of oauth, that's for authentication.
Description
If a user signup using oauth, its password will be set to an unguessable randomly generated one. If the user wants to login with a password later on, he can recover the password using the specific 'recovery' endpoint.
Be careful to the state parameter. It's needed to avoid CSRF attacks.