5 ms·
I think that the whole discussion around low-code is missing a pretty fundamental issue: most programming libraries suck. If I need, say, authentication, why d
by sbacic 5y ago
I think that the whole discussion around low-code is missing a pretty fundamental issue: most programming libraries suck.
If I need, say, authentication, why do I need to install a library and then read a bunch of documentation on how to use it? Why can't I simply plug it in (just like low-code!) and have it automatically work?
I think there is a lot of room to improve developer tooling and that the effort spent there would produce much greater rewards than developing a higher level abstraction, such as a pluggable authentication widget aimed at non-programmers.
- bostonsre 5y agoI think libraries are complicated so that they can be flexible and support many different use cases. You could release one library for authentication that works for one specific use case, but it would be useless for all others.
- tluyben2 5y agoAs far as I have seen, so far in my career, this is all 'not invented here' stuff. Most things, like auth go from 'oh no mate, we need 10000x more complicated stuff, that Keycloak thing will never fit!' and then, 6 months later there is something like keycloak but worse, far less features, more complex but replacable in no time by keycloak without touching the keycloak (no customizing) sourcecode. But we cannot because we now invested 6000 hours into it. So now it is ours and we will continue to say it is very complicated and so nothing fits our complicated use case. Alternatively, tell me your complicated auth flows that will not have users running away screaming and are, therefor, bad ideas and should be replaced by cookie cutter stuff. Because that is where all of these things end up.
- kayodelycaon 5y agoA number of Ruby on Rails applications use Devise for basic account management and authentication. It's about as close as you can get to a cookie-cutter experience. As long as you follow the workflow, it's pretty straight forward to handle. Drop in the plugin you want, configure the API keys, and then wire it into your User model. Then you can customize the urls, views, and emails. You still have to read a fair amount of documentation and a lot of developers don't like the extra up-front work and reinvent the wheel because it's "simpler".
- sbacic 5y agoI'm not sure I buy into it - I don't think it's necessary that even simple use cases need to be complicated in order for the whole to be flexible. The simple use cases should just be plug and play. If you want a different solution: here are the tools, here is the documentation, have fun.
- bsid 5y agoThis is what we're trying to solve at Clerk, (https://www.clerk.dev https://www.clerk.dev) and it's been harder than we've expected, especially in regards to local development environments. Although we think we’ve made it seamless! Would love your opinion. However, we're definitely not aiming it at non-programmers. I don't think completely general low/no-code solutions will ever take off. Everyone wants things far too custom, and at some point you won’t be able to beat the programming language of the time. Companies like retool are doing a great job in specific verticals — and I think it will always stay that way. I think the next generation of dev-tools are going to be pretty impressive, especially with how easy and modular React components are — I’m bullish that React will become “low-code”
- thescribbblr 5y agoAmazing. I mean I was feeling lazy to create auth+profile thing happy to know about what you guys are doing. Thank you so much for creating this!
- mrcartmenez 5y agoI see you too are familiar with Microsoft AD/B2C
- SahAssar 5y agoBecause authentication is coupled to authorization and authorization is coupled to business rules and data access. If your program does not deal with business rules and data access then it is probably a single-user program (that does not need authentication). I'm over-simplifying of course, but these things sound simple until you ask all the "but-then" and "what-if". If someone actually makes them simple in a way that still lets me cover those cases I'll be the first to stop writing authN/authZ code.
- npwr 5y agoAuthentication should definitely not be coupled with authorization. The only link between the two is an user ID. AWS very much decoupled authentication from authorization with Cognito and it works very well.
- sergiotapia 5y agoMeteorJS solved this years ago. You add a package and have everything working including oauth sources in 10 minutes flat. It was incredible. Shame MeteorJS died of his death. Sorry for your condolences.
- quickthrower2 5y agoTBH on asp.net you pretty much just follow a tutorial and you have signup, auth and users pretty quick. Let’s say this is 4 hours work for a programmer but .net newbie to set up a new project, add authentication including email/password and Google and get that deployed to azure. 4 hours from a business is a tiny amount of time. The upside over no code is owning the code and not being reliant on a dozen other indie startups for your business to continue to run