Yahoo! Developer Network Blog
« Previous | Main | Next »
May 19, 2009
OAuth Update #3, Revision A
All Yahoo! services using OAuth are now upgraded to the new OAuth 1.0a version of the protocol, resolving the session fixation security issue. The upgraded services include all Y!OS APIs (Contacts, Updates, Status, and Social Directory) and Fire Eagle. Users authorizing applications using OAuth 1.0a will not see the security interstitial screen that is displayed for apps that are still using the older 1.0 version of the protocol. For a short transitional period, we will continue to display the security interstitial screen for applications using OAuth 1.0, however we will soon require all applications to use 1.0a. Developers using Y!OS services should check out our updated OAuth documentation to see what’s changed in 1.0a, or you can just download and install the latest version of the Y!OS SDK to automatically upgrade your app to OAuth 1.0a, without any code changes. Open standards like OAuth benefit from having security professionals throughout the industry review and participate in the design of the protocol, as opposed to proprietary protocols, which have only a very small number of expert reviewers. Yahoo! is committed to open standards. We value all the hours of effort the OAuth community put into revising the protocol after the session fixation security issue was discovered. Keep on hacking!Allen Tom
Architect, Yahoo! Membership
Posted at May 19, 2009 11:42 AM | Permalink
Comments
Post a comment
Comment Policy: We encourage comments and look forward to hearing from you. Please note that Yahoo! may, in our sole discretion, remove comments if they are off topic, inappropriate, or otherwise violate our Terms of Service. Fields marked with asterisk '*' are required.
Subscribe
Recent Blog Articles
view all
YQL Open Table for Google Buzz now live
Tue, 09 Feb 2010
INSERT INTO twitter.status ...
Mon, 08 Feb 2010
Announcing the Yahoo! Brasil Open Hack Day 2010, 20-21 March
Mon, 08 Feb 2010
Marketing hacks, linchpins, and tech women of valor
Sun, 07 Feb 2010
Yahoo! India invites you to join the first India Hadoop Summit
Thu, 04 Feb 2010
Recent Links
Appcelerator Titanium + Yahoo YQL on Vimeo
Mon, 08 Feb 2010
Tue, 02 Feb 2010
PhoneGap | Cross platform mobile framework
Sat, 30 Jan 2010
Web developers can rule the iPad - O'Reilly Radar
Sat, 30 Jan 2010
rc3.org - Is the iPad the harbinger of doom for personal computing?
Thu, 28 Jan 2010
Archives
2010
2009
2008
2007
2006
2005
Recent Readers

