Hacker News new | ask | show | jobs
by magicalhippo 2065 days ago
No, I believe you got it 100% backwards.

See the diagram in the RFC[1] and section 1.3 just below it. Sure OAuth usually involves authentication, but OAuth doesn't really care how it's done.

Then again, not my field of expertise so I might be wrong.

[1]: https://tools.ietf.org/html/rfc6749#section-1.2