Move from OAuth 1.0a to OAuth 2.0 for OSM logins #1548
Labels
No labels
Android-shell
awaiting feedback
awaiting fix confirmation
bug
enhancement
Help Wanted
high-priority
huge
low-priority
Meta
NLNet
OSOC21:Cycling-OVL
Performance
question
search-ui-enhancement
Studio
Tailwind
Themes
UI
upstream-issue
usertest
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
MapComplete/MapComplete#1548
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
OSM's OAuth 1.0a is in the process of being deprecated, as discussed at https://github.com/openstreetmap/operations/issues/867. No timeline has been set, but we do not expect to shut off OAuth 1.0a this year. It would be good to move to OAuth 2.0 well before this time.
Hi,
This has come up with the security scan as well, so it is on the roadmap to do.
This is now implemented, thanks to the fact that the
osm-auth-library supports OAUth 2.0 too.I'll leave this in the dev branch for about a week, I'll merge into production in about two weeks.