Yahoo! Developer Network Blog
« Previous | Main | Next »
June 16, 2009
OAuth Update: New Streamlined User Experience, and Revision A
Over the years, many developers have asked us to make our Auth UIs (the user interface for logging in and verifying user ID and password) less jarring and disruptive. Until today, all of our authorization services, including OAuth, OpenID, and BBAuth used a "redirect" UI, which required sites to redirect the user's browser over to Yahoo! to ask for the user's approval before sharing the user's data. Many developers found this user experience (UX) disruptive: Confronting a user with a Yahoo! login screen after being redirected from the developer's site does not provide context for the user to understand why they're being prompted for their password, nor does it give the user a clear way back to the originating site. Due to the very real risk of phishing scams, we tell our users to never enter their Yahoo! password on any web page other than the Yahoo! login screen, and we actively encourage our users to set up a personalized Sign-in Seal to help protect them from being phished. Because of the phishing threat, we strongly believe that users should only enter their password on the Yahoo! login screen, which required sites using our Auth services to use the redirect UI, rather than using a more inline and contextual flow. We're very happy to announce that we've now updated our OAuth UI to be more contextual and streamlined. We've added more context for why the user is being prompted for their password, and we've formatted the UI to be displayable in a small popup window. For security reasons, we require that the popup window always be opened with the address bar displayed, clearly showing the URL of the Yahoo! login screen.Architect, Yahoo! Membership
Posted at June 16, 2009 5:30 PM | Permalink
Comments
We've enjoyed great success with Yahoo's OAuth. The developers, SDK and effectiveness have made it an important part of of our site.
I look forward to using the streamlined 600 x 435 version!
Posted by: Jason Feffer at June 16, 2009 11:42 PM
woohoo! this helps address a big problem for developers who are doing everything they can to successfully drive "conversion" in their apps.
Posted by: Will Aldrich at June 17, 2009 12:46 PM
When will we get something like the ClientLogin authentication process that google provides?
I understand the security standpoint yahoo has but for a mobile developer, launching the browser app and coming back is a tedious process.
See http://code.google.com/apis/gdata/auth.html#ClientLogin for reference.
Posted by: Jamal Abdou-Karim Bengeloun at June 20, 2009 1:24 PM
Post a comment
Comment Policy: We encourage comments and look forward to hearing from you. Please note that Yahoo! may, in our sole discretion, remove comments if they are off topic, inappropriate, or otherwise violate our Terms of Service. Fields marked with asterisk '*' are required.
Subscribe
Recent Blog Articles
view all
YQL Open Table for Google Buzz now live
Tue, 09 Feb 2010
INSERT INTO twitter.status ...
Mon, 08 Feb 2010
Announcing the Yahoo! Brasil Open Hack Day 2010, 20-21 March
Mon, 08 Feb 2010
Marketing hacks, linchpins, and tech women of valor
Sun, 07 Feb 2010
Yahoo! India invites you to join the first India Hadoop Summit
Thu, 04 Feb 2010
Recent Links
Appcelerator Titanium + Yahoo YQL on Vimeo
Mon, 08 Feb 2010
Tue, 02 Feb 2010
PhoneGap | Cross platform mobile framework
Sat, 30 Jan 2010
Web developers can rule the iPad - O'Reilly Radar
Sat, 30 Jan 2010
rc3.org - Is the iPad the harbinger of doom for personal computing?
Thu, 28 Jan 2010
Archives
2010
2009
2008
2007
2006
2005
Recent Readers

