How does pop-up window based Google OAuth work?

Viewed 31

I have been learning about OAuth recently, and observing site's that make use of OAuth. I have observed, when I attempt to login into Udemy using Google OAuth, it pop's open a new window where I can sign in with my Google account, and then it closes the popped open window after a successful sign in. And somehow Udemy get's to know that I have signed in with Google, which I am not sure how.

This looks to be very different from the regular Google OAuth based sign in on many other site's which load the Google sign in page in the same window and redirect it back to the original website that I was browsing without any pop up window. This process is currently my understanding of how OAuth generally works, so I am getting confused with how Udemy is doing it differently with a pop up window and without a redirect uri.

Can someone kindly explain how does pop up window based OAuth work ? Does it use cookies, if so, how is it access the cookie being generated from the pop up window ?

Steps that happen at Udemy for Google OAuth:

  1. User clicks Google sign in option on Udemy Log in page
  2. Google OAuth Pop Up Window, allowing the user to select from several accounts
  3. User selects their account and the Pop up window closes
  4. User is taken to Udemy with the user being logged in
0 Answers
Related