In this 3-part video series, I walk through the OAuth 2.0 Authorization Code Flow end-to-end, using Salesforce as the client and custom Node.js services as the Authorization Server and Resource Server. The focus is on understanding what actually happens behind each step of the OAuth flow by implementing and demonstrating it hands-on.
Part 1 — Setup & Authorization Request
- Understand the four OAuth 2.0 roles: Resource Owner, Client, Authorization Server and Resource Server
- Build custom Authorization Server and Resource Server using Node.js
- Use ngrok to expose the local services to Salesforce
- Understand the overall Authorization Code Flow
- Implement the initial authorization request with
response_type,client_id,redirect_uriandstate - Understand front-channel communication and the Authorization Endpoint
Part 2 — Authorization Code & Access Token
- Authenticate the Resource Owner
- Implement the consent step
- Generate and return the authorization code
- Redirect back to Salesforce with
codeandstate - Validate the state parameter
- Exchange the authorization code for an access token
- Explore the Token Endpoint, client authentication and
grant_type - Implement authorization-code expiry and single-use validation
Part 3 — Accessing the Protected Resource
- Use the access token to call the Resource Server
- Make the protected-resource request using HTTP GET
- Send the token using the Authorization header with the Bearer authentication scheme
- Validate the access token at the Resource Server
- Check token existence and expiry
- Return the protected resource
- Understand why the Authorization Code Flow uses an intermediate authorization code instead of sending the access token through the browser
Together, the three videos demonstrate the complete Authorization Code Flow from the initial authorization request all the way to accessing the protected resource.
Node JS and Ggrok – Click Here
