Skip to content

Oauth2 Security considerations, vague? #1858

Description

@Crow-Control

The security considerations for using oauth state the following:

This means that every token has full access to the complete account including read and write permission to the stored files.

and

Without scopes and restrictable access it is not recommended to use a Nextcloud instance as a user authentication service.

I understand that it's risky giving any service access to the tokens themselves.
But in case we use something like pusher/oauth2_proxy do these security considerations still apply? The underlaying app shouldn't get access to those tokens would it?

Activity

  1. skjnldsv commented on Mar 3, 2020

    @skjnldsv
    Member
  2. ChristophWurst commented on Mar 3, 2020

    @ChristophWurst
    Member

    Added by #1685, original ticket #1683

  3. skjnldsv commented on May 14, 2026

    @skjnldsv
    Member

    Still present. admin_manual/configuration_server/oauth2.rst lines 41-43 warn that tokens have full account access and that using Nextcloud as an auth service is not recommended, but the note doesn't distinguish between two very different use cases:

    1. An app receives the OAuth2 token and uses it to call Nextcloud APIs (full access warning fully applies).
    2. A proxy like oauth2_proxy uses Nextcloud only for the authentication step; the underlying application never sees or uses the token (the full-access warning doesn't apply in the same way).

    Adding a clarification that the warning applies to case 1, and that using Nextcloud purely as an identity provider (without the app receiving the token) is a different and less risky setup, would make this note more accurate and actionable.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions