Re: [Openstack] [Keystone] Why not OAuth 2.0 provider?

2016-06-28 Thread Adam Young
On 06/28/2016 03:18 AM, 林自均 wrote: Hi Steve, Thanks for your explanation! I have some further questions: You said that OS-OAUTH doesn't make Keystone a proper OAuth provider, so what is missing? Can name some of the missing parts? Another thing, a backlog started by you proposed to unify

Re: [Openstack] [Keystone] Why not OAuth 2.0 provider?

2016-06-28 Thread 林自均
Hi Steve, Thanks for your explanation! I have some further questions: You said that OS-OAUTH doesn't make Keystone a proper OAuth provider, so what is missing? Can name some of the missing parts? Another thing, a backlog started by you proposed to unify delegation features [1]. Its spec uses

Re: [Openstack] [Keystone] Why not OAuth 2.0 provider?

2016-06-28 Thread Steve Martinelli
So, the os-oauth routes you mention in the documentation do not make keystone a proper oauth provider. We simply perform delegation (one user handing some level of permission on a project to another entity) with the standard flow established in the oauth1.0b specification. Historically we chose