How to auth backend service throught mobile app with Oauth2?

Viewed 260

Help me please to understand correct flow to SSO with a mobile app for backend services

Now I'm using the next scheme: enter image description here

  1. My unauthorized mobile app wants to auth in my service through SSO (facebook and google). It has clientId, clientSecret and required scopes for My service.
  2. My mobile app auth with vendor SDK, for example, on Facebook.
  3. My mobile app give back authorization token.
  4. My mobile app sends authorization token in the auth request to My service.
  5. My service uses this token to get information about a user from a remote identity provider. For example, get a user identifier or email with Facebook Graph API. This identity used to authenticate and authorize a user (my own RDB).
  6. My service return JWT token to My mobile app (if auth success). This token is used for the next request to My service API.

Is it correct to send Oauth2 token from the app to backend?

Can you point out the ​errors of the current approach?

0 Answers
Related