<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>认证 on Answer</title>
    <link>https://answer.freetools.me/tags/%E8%AE%A4%E8%AF%81/</link>
    <description>Recent content in 认证 on Answer</description>
    <generator>Hugo -- 0.152.2</generator>
    <language>zh-cn</language>
    <lastBuildDate>Sun, 08 Mar 2026 19:14:52 +0800</lastBuildDate>
    <atom:link href="https://answer.freetools.me/tags/%E8%AE%A4%E8%AF%81/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>JWT认证入门：从令牌结构到安全验证的完整指南</title>
      <link>https://answer.freetools.me/jwt%E8%AE%A4%E8%AF%81%E5%85%A5%E9%97%A8%E4%BB%8E%E4%BB%A4%E7%89%8C%E7%BB%93%E6%9E%84%E5%88%B0%E5%AE%89%E5%85%A8%E9%AA%8C%E8%AF%81%E7%9A%84%E5%AE%8C%E6%95%B4%E6%8C%87%E5%8D%97/</link>
      <pubDate>Sun, 08 Mar 2026 19:14:52 +0800</pubDate>
      <guid>https://answer.freetools.me/jwt%E8%AE%A4%E8%AF%81%E5%85%A5%E9%97%A8%E4%BB%8E%E4%BB%A4%E7%89%8C%E7%BB%93%E6%9E%84%E5%88%B0%E5%AE%89%E5%85%A8%E9%AA%8C%E8%AF%81%E7%9A%84%E5%AE%8C%E6%95%B4%E6%8C%87%E5%8D%97/</guid>
      <description>一篇系统性的JWT入门教程，从最基础的概念开始，详细讲解JWT的Header、Payload、Signature三部分结构，认证工作流程，与Session的对比，签名算法选择，以及安全最佳实践。</description>
    </item>
    <item>
      <title>OAuth 2.0授权框架：从授权码流程到PKCE的完整技术指南</title>
      <link>https://answer.freetools.me/oauth-2.0%E6%8E%88%E6%9D%83%E6%A1%86%E6%9E%B6%E4%BB%8E%E6%8E%88%E6%9D%83%E7%A0%81%E6%B5%81%E7%A8%8B%E5%88%B0pkce%E7%9A%84%E5%AE%8C%E6%95%B4%E6%8A%80%E6%9C%AF%E6%8C%87%E5%8D%97/</link>
      <pubDate>Sun, 08 Mar 2026 18:17:43 +0800</pubDate>
      <guid>https://answer.freetools.me/oauth-2.0%E6%8E%88%E6%9D%83%E6%A1%86%E6%9E%B6%E4%BB%8E%E6%8E%88%E6%9D%83%E7%A0%81%E6%B5%81%E7%A8%8B%E5%88%B0pkce%E7%9A%84%E5%AE%8C%E6%95%B4%E6%8A%80%E6%9C%AF%E6%8C%87%E5%8D%97/</guid>
      <description>一篇系统性的OAuth 2.0授权框架教程，从第三方登录场景引入，详细讲解授权码流程、PKCE扩展、Token管理、JWT结构、授权服务器端点、OpenID Connect、OAuth 2.1规范、常见安全漏洞与防范措施。内容涵盖四种授权类型对比、Access Token与Refresh Token机制、Token存储安全考量，以及不同应用场景的实践建议，适合希望深入理解OAuth工作原理的开发者阅读。</description>
    </item>
    <item>
      <title>OAuth 2.0的隐形陷阱：为什么这个授权标准让无数开发者踩坑</title>
      <link>https://answer.freetools.me/oauth-2.0%E7%9A%84%E9%9A%90%E5%BD%A2%E9%99%B7%E9%98%B1%E4%B8%BA%E4%BB%80%E4%B9%88%E8%BF%99%E4%B8%AA%E6%8E%88%E6%9D%83%E6%A0%87%E5%87%86%E8%AE%A9%E6%97%A0%E6%95%B0%E5%BC%80%E5%8F%91%E8%80%85%E8%B8%A9%E5%9D%91/</link>
      <pubDate>Sat, 07 Mar 2026 04:23:03 +0800</pubDate>
      <guid>https://answer.freetools.me/oauth-2.0%E7%9A%84%E9%9A%90%E5%BD%A2%E9%99%B7%E9%98%B1%E4%B8%BA%E4%BB%80%E4%B9%88%E8%BF%99%E4%B8%AA%E6%8E%88%E6%9D%83%E6%A0%87%E5%87%86%E8%AE%A9%E6%97%A0%E6%95%B0%E5%BC%80%E5%8F%91%E8%80%85%E8%B8%A9%E5%9D%91/</guid>
      <description>深入解析OAuth 2.0协议的设计缺陷与实现陷阱。从Eran Hammer辞职事件到RFC 9700安全最佳实践，系统梳理CSRF攻击、redirect_uri绕过、授权码注入、mix-up攻击等核心威胁，结合Grammarly、Vidio、Bukalapak真实案例，揭示OAuth安全实现的完整技术路径。</description>
    </item>
  </channel>
</rss>
