OAuth (Open Authorization) ã¯ããŠãŒã¶ãŒã®èªèšŒãšèªå¯ã®ããã®ãªãŒãã³æšæºã§ãããWebãã¢ãã€ã«ãããã³ããã¯ãšã³ã ã¢ããªã±ãŒã·ã§ã³ã®ã³ã³ããã¹ãã§äžè¬çã«äœ¿çšãããŸããããã¯åºãæ¡çšãããŠãããããã³ã«ã§ããµãŒãããŒãã£ã®ã¢ããªã±ãŒã·ã§ã³ãããŠãŒã¶ãŒåããã¹ã¯ãŒããªã©ã®æ©å¯ã®è³æ Œæ å ±ãå ±æããããšãªããä»ã®ã·ã¹ãã ã§ãã¹ããããŠãããŠãŒã¶ãŒã®ä¿è·ããããªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ããããã«ãªããŸãã OAuth ã¯ãå®å šã§åçåãããèªèšŒããã»ã¹ãæäŸãããŠãŒã¶ãŒ ãšã¯ã¹ããªãšã³ã¹ãåäžãããæ©å¯ããŒã¿ã®åãæ±ãã«äŒŽããªã¹ã¯ã軜æžããããšãç®çãšããŠããŸãã
OAuth ãã¬ãŒã ã¯ãŒã¯ã䜿çšãããšãã¢ã¯ã»ã¹ ããŒã¯ã³ã®äœæãå¯èœã«ãªããŸããã¢ã¯ã»ã¹ ããŒã¯ã³ã¯ããŠãŒã¶ãŒã®ä¿è·ããããªãœãŒã¹ãšå¯Ÿè©±ããããã®éå®çãªã¢ã¯ã»ã¹èš±å¯ããµãŒãããŒã㣠ã¢ããªã±ãŒã·ã§ã³ã«ä»äžããäžæã®äžæçãªèªèšŒæ å ±ã§ããããã«ããããŠãŒã¶ãŒã¯ãµãŒãããŒã㣠ã¢ããªã«ãã£ãŠèŠæ±ãããã¢ã¯ã»ã¹èš±å¯ãæç€ºçã«æ¿èªããããšã§ããŒã¿ã®å¶åŸ¡ãç¶æã§ãããšåæã«ãã¢ããªèªäœã¯ãŠãŒã¶ãŒã®è³æ Œæ å ±ãçŽæ¥åŠçããã«å¿ èŠãªãªãœãŒã¹ã«ã¢ã¯ã»ã¹ããããã®å®å šã§æšæºåãããæ¹æ³ãç²åŸã§ããŸãã
ãã®èŠæ Œã®ææ°ããŒãžã§ã³ã§ãã OAuth 2.0 ã¯ãFacebookãGoogleãMicrosoft ãªã©ã®äž»èŠãªãã¯ãããžãŒäŒæ¥ããã©ãããã©ãŒã ã«ãã£ãŠãµããŒããããŠããŸãã Cloud Security Alliance ã«ãããšãWeb ã¢ããªã±ãŒã·ã§ã³ã®çŽ 93% ããŠãŒã¶ãŒèªèšŒã« OAuth ã䜿çšããŠãããå®å šã§ãŠãŒã¶ãŒãã¬ã³ããªãŒãªèªèšŒæ¹æ³ã®æ¡çšã«åããæ¥çã®å€§ããªå€åã衚ããŠããŸãã
OAuth ã¯æè»ãªã¢ãŒããã¯ãã£ã§èšèšãããŠãããããŸããŸãªçš®é¡ã®ã¢ããªã±ãŒã·ã§ã³ããã©ãããã©ãŒã ãã»ãã¥ãªãã£èŠä»¶ã«é©å¿ããŠãµããŒãã§ããŸãããã®æšæºã§ã¯ãã¢ããªã±ãŒã·ã§ã³ã®ãŠãŒã¹ã±ãŒã¹ãšã»ãã¥ãªãã£ã®ããŒãºã«åºã¥ããŠéžæã§ãã 4 ã€ã®ç°ãªãèš±å¯ã¿ã€ã (èªèšŒã³ãŒããæé»çããã¹ã¯ãŒããããã³ã¯ã©ã€ã¢ã³ãè³æ Œæ å ±) ãæäŸãããŠããŸããåä»äžã¿ã€ãã¯ã¢ã¯ã»ã¹ ããŒã¯ã³ãååŸããç¹å®ã®æ¹æ³ã衚ããå®éã«ééããããŸããŸãªã¢ããªã±ãŒã·ã§ã³ ã·ããªãªã«å¯Ÿå¿ããŸãã
AppMasterno-codeãã©ãããã©ãŒã ã®ã³ã³ããã¹ãã§ã¯ãOAuth ãçæããã Webãã¢ãã€ã«ãããã³ããã¯ãšã³ã ã¢ããªã±ãŒã·ã§ã³ã«ã·ãŒã ã¬ã¹ã«çµ±åã§ããŸãã AppMasterã®çŽæçãªããžã¥ã¢ã« ãã¶ã€ã³ ããŒã«ãšäž»èŠãª OAuth ãããã€ããŒã®ãµããŒãã«ãããã客æ§ã¯ããŠãŒã¶ãŒèªèšŒãšèªå¯ã®äœã¬ãã«ã®è©³çްã§ã¯ãªããäžæ žãšãªãããžãã¹ ããã»ã¹ã«çŠç¹ãåœãŠãŠããŠãŒã¶ãŒåãã«å®å šãªèªèšŒãããŒãè¿ éã«èšå®ã§ããŸããããã«ã AppMasterãæäŸãã匷åãªããŒã«ãšæ©èœã®ã»ããã䜿çšãããšã顧客ã¯ããŒã¿ããŒã¹ ã¹ããŒããããžãã¹ ããã»ã¹ãAPI endpointsç°¡åã«äœæããã³ç®¡çã§ãããšåæã«ãOAuth æšæºã«ãã£ãŠæäŸãããåºæã®ã»ãã¥ãªãã£ãšã¹ã±ãŒã©ããªãã£ã®æ©æµãåããããšãã§ããŸãã
OAuth ã¯ãæ»æå¯Ÿè±¡é åãå¶éããæ©å¯æ§ã®é«ããŠãŒã¶ãŒè³æ Œæ å ±ã®ä¿åãšç®¡çã«é¢é£ãããªã¹ã¯ã軜æžããããšã§ãã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£äœå¶ã匷åããäžã§éèŠãªåœ¹å²ãæãããŸããããã«ãèªèšŒããã»ã¹ãä¿¡é Œã§ãã OAuth ãããã€ããŒã«ã¢ãŠããœãŒã·ã³ã°ããããšã§ãã¢ããªã±ãŒã·ã§ã³éçºè ã¯ãå€èŠçŽ èªèšŒ (MFA) ããªã¹ã¯ããŒã¹èªèšŒãªã©ã®ãããã€ããŒã®æ¢åã®ã»ãã¥ãªãã£å¯ŸçãæŽ»çšããŠãå šäœçãªã»ãã¥ãªãã£ãããã«åäžãããäžæ£ã¢ã¯ã»ã¹ã®å¯èœæ§ãæžããããšãã§ããŸãããŠãŒã¶ãŒããŒã¿ã«ã
OAuth å®è£ ã®äžäŸã¯ãå€ãã® Web ãµã€ããã¢ããªã±ãŒã·ã§ã³ã§äžè¬çã«èŠããããGoogle ã§ãµã€ã³ã€ã³ãæ©èœã§ãã Google ã¢ã«ãŠã³ãã䜿çšããŠãµã€ã³ã€ã³ããããšãéžæãããŠãŒã¶ãŒã¯ãGoogle ããã¹ãããããŒãžã«ãªãã€ã¬ã¯ããããããã§èªåèªèº«ãèªèšŒããèŠæ±ãããæš©éãæ¿èªããŸããæ¿èªãæåãããšãGoogle ã¯ã¢ããªã±ãŒã·ã§ã³ã«å¯ŸããŠèŠæ±ãããæš©éãå«ãã¢ã¯ã»ã¹ ããŒã¯ã³ãçºè¡ããŸãããã®åŸãã¢ããªã±ãŒã·ã§ã³ã¯ãã®ã¢ã¯ã»ã¹ ããŒã¯ã³ã䜿çšããŠãä»äžãããæš©éã®ç¯å²å ã§ãŠãŒã¶ãŒã®æ å ±ããªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ããŸããããŠãŒã¶ãŒã®èªèšŒæ å ±ã¯ Google ã«å®å šã«ä¿åããããŸãŸã«ãªããŸãã
OAuth ã¯ããŠãŒã¶ãŒã®èªèšŒãšèªå¯ã«ãããå€§å¹ ãªé²æ©ã衚ããã¢ããªã±ãŒã·ã§ã³ããŠãŒã¶ãŒã«ä»£ãã£ãŠä¿è·ããããªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ããããã«ãããå®å šã§æšæºåããããŠãŒã¶ãŒãã¬ã³ããªãŒãªæ¹æ³ãæäŸããŸãã AppMasterno-codeãã©ãããã©ãŒã ã§ OAuth ãæŽ»çšããããšã§ãéçºè ã¯ãçŸä»£ã®ããžãã¹ã®å¢å€§ããéèŠãæºããã匷åã§ã¹ã±ãŒã©ãã«ã§å®å šãªã¢ããªã±ãŒã·ã§ã³ãè¿ éã«æ§ç¯ããã³å±éããããšãã§ãããŸããŸãçžäºæ¥ç¶ããããŒã¿ããªãã³ã«ãªã£ãŠããç°å¢ã§æ©å¯æ§ã®é«ããŠãŒã¶ãŒ ããŒã¿ãšãªãœãŒã¹ã確å®ã«ä¿è·ã§ããŸããäžçã