OAuth 2.0 Authorization Code Flow — Hands-on Implementation

In this 3-part video series, I walk through the OAuth 2.0 Authorization Code Flow end-to-end, using Salesforce as the client and custom Node.js services as the Authorization Server and Resource Server. The focus is on understanding what actually happens behind each step of the OAuth flow by implementing and demonstrating it hands-on.

Part 1 — Setup & Authorization Request

  • Understand the four OAuth 2.0 roles: Resource Owner, Client, Authorization Server and Resource Server
  • Build custom Authorization Server and Resource Server using Node.js
  • Use ngrok to expose the local services to Salesforce
  • Understand the overall Authorization Code Flow
  • Implement the initial authorization request with response_type, client_id, redirect_uri and state
  • Understand front-channel communication and the Authorization Endpoint

Part 2 — Authorization Code & Access Token

  • Authenticate the Resource Owner
  • Implement the consent step
  • Generate and return the authorization code
  • Redirect back to Salesforce with code and state
  • Validate the state parameter
  • Exchange the authorization code for an access token
  • Explore the Token Endpoint, client authentication and grant_type
  • Implement authorization-code expiry and single-use validation

Part 3 — Accessing the Protected Resource

  • Use the access token to call the Resource Server
  • Make the protected-resource request using HTTP GET
  • Send the token using the Authorization header with the Bearer authentication scheme
  • Validate the access token at the Resource Server
  • Check token existence and expiry
  • Return the protected resource
  • Understand why the Authorization Code Flow uses an intermediate authorization code instead of sending the access token through the browser

Together, the three videos demonstrate the complete Authorization Code Flow from the initial authorization request all the way to accessing the protected resource.

Node JS and Ggrok – Click Here

Leave a Reply