èªå¯ã³ãŒãã°ã©ã³ãã¯ãã¢ã¯ã»ã¹ããŒã¯ã³ãååŸãããŠãŒã¶ãŒèªèšŒã®ã³ã³ããã¹ãã§ API ãä»ããŠã¯ã©ã€ã¢ã³ããä¿è·ããããªãœãŒã¹ã«ã¢ã¯ã»ã¹ããããšãèªå¯ããããã®ãäžè¬çã§å®å šãªæ¹æ³ã§ããããã¯ãOAuth 2.0 ãã¬ãŒã ã¯ãŒã¯ã®äžéšã§ãããæ©å¯æ å ±ãä¿è·ããè³æ Œæ å ±ã®äžå¿ èŠãªå ±æãé¿ããããã«ãå€ãã®ã¢ããªã±ãŒã·ã§ã³ã§å§ä»»ãããæ¿èªã®ããã«ãã䜿çšãããæ¥çæšæºãããã³ã«ã§ããããã«ãOAuth 2.0 ã§ã¯ãã¯ã©ã€ã¢ã³ãããªãœãŒã¹ææè (ãŠãŒã¶ãŒ)ããªãœãŒã¹ ãµãŒããŒãããã³èªå¯ãµãŒããŒã®éã§åœ¹å²ãåé¢ã§ãããããæœåšçãªè匱æ§ã®ãªã¹ã¯ã軜æžãããŸãã Authorization Code Grant ã¯ãã¯ã©ã€ã¢ã³ããã¯ã©ã€ã¢ã³ã ã·ãŒã¯ã¬ãããå®å šã«ä¿åã§ããæ©å¯ã¯ã©ã€ã¢ã³ã (Web ã¢ããªã±ãŒã·ã§ã³ãªã©) ã«ç¹ã«é©ããŠããŸãã
èªå¯ã³ãŒãä»äžã®ä»çµã¿:
- ã¯ã©ã€ã¢ã³ãã¯ããªãœãŒã¹ææè ãèªå¯ãµãŒããŒã«æç€ºããŠãèªå¯ãªã¯ãšã¹ããéå§ããŸããããã¯éåžžãã¯ã©ã€ã¢ã³ãã® IDãèŠæ±ãããã¹ã³ãŒã (æš©é)ããªãã€ã¬ã¯ã URI ãªã©ã®ãã©ã¡ãŒã¿ãŒãå«ãèªå¯ãµãŒããŒã® URL ã«ãŠãŒã¶ãŒããªãã€ã¬ã¯ãããããšã«ãã£ãŠè¡ãããŸãã
- èªå¯ãµãŒããŒã¯ããŠãŒã¶ãŒã®è³æ Œæ å ±ãèŠæ±ããããæ¢åã®èªèšŒæžã¿ã»ãã·ã§ã³ãåå©çšããããšã«ãã£ãŠããªãœãŒã¹ææè ãèªèšŒããŸããæ¬¡ã«ããŠãŒã¶ãŒã«åæç»é¢ã衚瀺ããããŠãŒã¶ãŒã¯ä¿è·ããããªãœãŒã¹ãžã®ã¯ã©ã€ã¢ã³ãã®ã¢ã¯ã»ã¹èŠæ±ãèš±å¯ãŸãã¯æåŠã§ããŸãã
- åæããã»ã¹ãå®äºãããšãèªå¯ãµãŒããŒã¯ãŠãŒã¶ãŒãã¯ã©ã€ã¢ã³ãã®æå®ããããªãã€ã¬ã¯ã URI ã«ãªãã€ã¬ã¯ãããã¯ãšãª ãã©ã¡ãŒã¿ãšããŠèªå¯ã³ãŒãã远å ããŸãã
- 次ã«ã¯ã©ã€ã¢ã³ãã¯ãèªå¯ãµãŒããŒã«å¯ŸããŠå®å šãªããã¯ãã£ãã«èŠæ±ãè¡ãããšã«ãããã¢ã¯ã»ã¹ ããŒã¯ã³ãšãªãã·ã§ã³ã®ãªãã¬ãã·ã¥ ããŒã¯ã³ã®èªå¯ã³ãŒãã亀æããŸãããã®ãªã¯ãšã¹ãã«ã¯ãã¯ã©ã€ã¢ã³ãã® ID ãšç§å¯ãèªèšŒã³ãŒããããã³å ã®ãªãã€ã¬ã¯ã URI ãå«ãŸããŸãã
- èªå¯ãµãŒããŒã¯ãªã¯ãšã¹ããæ€èšŒããæäŸãããèªå¯ã³ãŒãã®æå¹æéãåããŠãããã以åã«äœ¿çšãããŠããªãããšã確èªããŸãããŸããå ã®ãªãã€ã¬ã¯ã URI ããã®ãªã¯ãšã¹ãã§éä¿¡ããããã®ãšç §åããŸãããã¹ãŠãæ£åžžã§ããã°ããµãŒããŒã¯èŠæ±ãããã¢ã¯ã»ã¹ ããŒã¯ã³ãšãªãã¬ãã·ã¥ ããŒã¯ã³ãè¿ããŸãã
- ããã§ãã¯ã©ã€ã¢ã³ãã¯ã¢ã¯ã»ã¹ ããŒã¯ã³ã䜿çšããŠããªãœãŒã¹ ãµãŒããŒããä¿è·ããããªãœãŒã¹ãèŠæ±ã§ããããã«ãªããŸããéåžžãããŒã¯ã³ã¯ãªã¯ãšã¹ãã® Authorization ããããŒå ã®ãã¢ã©ãŒ ããŒã¯ã³ãšããŠæž¡ãããŸãã
AppMasterno-codeãã©ãããã©ãŒã ã§ã¯ãèŠèŠçã«äœæãããããžãã¹ ããã»ã¹ãéããŠèªå¯ã³ãŒãä»äžã®èšå®ãè¡ãããšãã§ããŸããããã«ããã AppMasterã¢ããªã±ãŒã·ã§ã³ã¯å€éšã® OAuth 2.0 æºæ API ãšå®å šã«å¯Ÿè©±ã§ããããã«ãªãããŠãŒã¶ãŒã«ã·ãŒã ã¬ã¹ã§å®å šãªãšã¯ã¹ããªãšã³ã¹ãæäŸã§ããŸããããã«ã AppMasterã«ãã£ãŠçæããã REST API ãš WSS endpointsã«ãããOAuth 2.0 ãããã³ã«ã®é©åãªå®è£ ãä¿èšŒãããŸãã
èªå¯ã³ãŒãä»äžã¯æãå®å šãª OAuth 2.0 ä»äžã¿ã€ãã§ãããWeb ã¢ããªã±ãŒã·ã§ã³ã«åºã䜿çšãããŠããŸãããå¿ èŠãªã»ãã¥ãªãã£å¯Ÿçãæ€èšããããšãéèŠã§ããã»ãã¥ãªãã£ã®éèŠãªåŽé¢ã¯ãããŒã¯ã³äº€æäžã«äœ¿çšãããã¯ã©ã€ã¢ã³ãã®ç§å¯ãä¿è·ããããšã§ãããããªã㯠ã¯ã©ã€ã¢ã³ã (ã¢ãã€ã« ã¢ããªã±ãŒã·ã§ã³ãã·ã³ã°ã« ããŒãž ã¢ããªã±ãŒã·ã§ã³ãªã©) ã®å Žåãã¯ã©ã€ã¢ã³ã ã·ãŒã¯ã¬ãããå®å šã«ä¿åã§ããªãå Žåã§ãããã»ã¹ãä¿è·ããããã«ãProof Key for Code Exchange (PKCE) æ¡åŒµæ©èœã䜿çšããããšããå§ãããŸãã
æ¥çã®ååãèŠããšãOAuth 2.0 ãš Authorization Code Grant ã¯å§ä»»ãããæ¿èªãåŠçããå®å šãã€åççãªæ¹æ³ãæäŸããããããã®å°å ¥ãçå®ã«å¢å ããŠããããšã瀺ãããŠããŸãã AppMasterã®no-codeãã©ãããã©ãŒã ã䜿çšãããšãAuthorization Code Grant ã®å®è£ ãšç®¡çããã管çãããããªããäŒæ¥ãã»ãã¥ãªãã£èŠä»¶ãå¹ççã«æºããããŠãŒã¶ãŒ ãšã¯ã¹ããªãšã³ã¹ãåäžãããã¹ã±ãŒã©ããªãã£ãç¶æã§ããããã«ãªããŸãã
çµè«ãšããŠãèªå¯ã³ãŒãã°ã©ã³ãã¯ãå§ä»»ãããèªå¯ãéããŠä¿è·ããããªãœãŒã¹ãžã®å®å šãªã¢ã¯ã»ã¹ãå¯èœã«ãã OAuth 2.0 ãã¬ãŒã ã¯ãŒã¯ã®éèŠãªéšåã§ãããŠãŒã¶ãŒèªèšŒã®ããã®å ç¢ãªæ¥çæšæºãœãªã¥ãŒã·ã§ã³ãæäŸãããŠãŒã¶ãŒ ããŒã¿ã®æ©å¯æ§ãšå®å šæ§ãä¿èšŒããŸãã AppMasterno-codeãã©ãããã©ãŒã ã¯ããã®ãããªèªèšŒã¹ããŒã ã®å®è£ ãšç®¡çã®ããã»ã¹ãå€§å¹ ã«ç°¡çŽ åããã¯ã©ã€ã¢ã³ããããŸããŸãªãŠãŒã¹ã±ãŒã¹åãã«å®å šã§ã¹ã±ãŒã©ãã«ã§ã³ã¹ãå¹çã®é«ãã¢ããªã±ãŒã·ã§ã³ãè¿ éã«äœæã§ããããã«ããŸãã