5 ms·
What are some of the libraries you're thinking of?
by Merad 5y ago
What are some of the libraries you're thinking of?
- keithnz 5y agoI'd like to see them to roll their own identity platform after IdentityServer went close source.
- crobibero 5y agoIdentity server is still open source, it just has a much more restrictive license and is paid. https://github.com/DuendeSoftware/IdentityServer https://github.com/DuendeSoftware/IdentityServer
- keithnz 5y agook, not closed, but restricted use. I think Microsoft should do (or buy Duende) their own platform. I've swapped to using keycloak, which is really nice, but it's a whole different world than .net
- ptx 5y agoThat's not open source. The term "open source" (in the context of computer software) refers to a specific set of criteria (with some disagreement on philosophy and minor details[1][2][3]) that include the right to modify, redistribute and to use for any purpose. The term originates from the open source movement which branched off from the free software movement. If open source meant simply that the source code is available, Windows would also have to be considered open source, as Microsoft makes the code available to some of its customers. This is not how the term is generally understood. [1] https://www.gnu.org/philosophy/free-sw https://www.gnu.org/philosophy/free-sw [2] https://opensource.org/docs/definition.html https://opensource.org/docs/definition.html [3] https://www.debian.org/intro/free https://www.debian.org/intro/free
- jbogard 5y agoIdentityServer is still Apache 2.0, that has not changed.
- zvrba 5y agoWho is "them"? Microsoft? https://docs.microsoft.com/en-us/azure/active-directory/develop/ https://docs.microsoft.com/en-us/azure/active-directory/deve...
- keithnz 5y agothat lets you connect to identity platforms.
- oaiey 5y agoI agree. However a very difficult space. From one side they have commercials offerings (Active Directory and the variant within Azure). On the other the identity and authorization space has dozens of standards and the security space is changing primitives every day. It is extremely expensive and is permanently blocking resources from doing other things. That is also the reason IdentityServer is now under commercial license.
- manigandham 5y ago.NET already has an identity platform (ASP.NET Identity) that provides authentication/authorization with various backends. IdentityServer is a token server that speaks OAuth/OIDC and provides federation to other user directories (ASP.NET Identity or Azure Directory or anything else). IdentityServer4 is still open-source and available. There's a new version by Duende with commercial licensing, or various alternatives like OpenIddict [1]. OAuth/OIDC is a well-supported standard so you can also use servers in other languages like Ory [2]. Microsoft's team did consider making their own token server but there was considerable pushback from the community because it would have a negative effect on open-source, and wouldn't add anything new compared to existing projects while taking resources from other framework features. 1. https://github.com/openiddict/openiddict-core https://github.com/openiddict/openiddict-core 2. https://www.ory.sh/open-source https://www.ory.sh/open-source
- jbogard 5y agoIdentityServer is not closed source, it is still Apache 2.0.
- vp8989 5y agoThe Confluent.Kafka one, the AWS .NET SDK (though this is improving), the old MySQL one was really bad. My impression from reading the code and GitHub issues is that they're not maintained by real ".NET people" who are plugged in to all the fine details and best practices of the framework and the runtime. StackExchange.Redis is a good example of one that is independent of MS but still very high quality.
- bgrainger 5y agoI'm the author of what you might call the "new" MySQL ADO.NET library: https://github.com/mysql-net/MySqlConnector https://github.com/mysql-net/MySqlConnector I agree with your impression that developers of the other library don't seem to be "plugged in to" the .NET ecosystem. As an independent developer (not affiliated with Oracle or Microsoft), I've been able to influence GitHub PRs that shape the ADO.NET API for .NET 6.0, just by showing up and contributing; I haven't seen anyone from the Oracle MySQL team participating. Meanwhile, they violate basic principles of the .NET Framework Design Guidelines that have been around for over a decade (https://docs.microsoft.com/en-us/dotnet/standard/design-guidelines/ https://docs.microsoft.com/en-us/dotnet/standard/design-guid...), which makes their library feel alien to a .NET programmer (regardless of the quality issues it might have).
- vp8989 5y agoYeh I should have mentioned MySqlConnector as another example of a high quality .NET library, my apologies. We ripped out the Oracle MySQL library at work and put MySqlConnector in. The high quality documentation made it really easy to understand and make adjustments for the differing behaviors between the 2 libraries. Any time I've poked into the code to try to understand some fine detail of it, I've always found it very easy to quickly understand what could be going on. It's great.