4 ms·
I like SAML because it does not involve http requests to fetch user profile (unless I'm missing something and OIDC allows that too). The whole user profile come
by jeff_vader 7y ago
I like SAML because it does not involve http requests to fetch user profile (unless I'm missing something and OIDC allows that too). The whole user profile comes with the signed or encrypted payload.
As a result you can have identity provider sitting in an unreachable / private network.
Or.. Your identity provider doesn't even have to be a network service at all. We have some integration tests around systems using SAML for authentication. SAML authentication statements in test environments are generated by the test suite and fed to SPs via Selenium controlled browser.
- lvh 7y agoThe OIDC "id token" is a JWT that contains identity assertions, just like SAML would. You can go fetch the profile via HTTP, but that's mostly because major providers have quietly conceded that JWT is a nightmare, and encoded that fact in their API.
- throwaway3157 7y agoWhat do you mean here? Encoded in their API? And If they don’t like JWT, why don’t they use something else?
- lvh 7y agoMajor IdPs tend to provide an endpoint where you can send them the JWT, they validate it and return its contents as a plain JSON response. You're effectively trading JWT parsing for HTTPS. They can't walk JWT back now without breaking existing apps, because parsing it yourself was advertised as an option.