3 ms·
Using OAuth2 for solving first party sign in is such a pain. Synchronizing refresh token requests, storing sessions on top of your access token, going through a
by vexcaustic 5y ago
Using OAuth2 for solving first party sign in is such a pain. Synchronizing refresh token requests, storing sessions on top of your access token, going through a consent grant, making sure you use the right flow (implicit is out? auth code? with pkce? without?)
There is some really good open source software emerging like https://github.com/ory/kratos https://github.com/ory/kratos which has APIs for native app flows, single page apps, server side apps and doesn‘t rely on protocols intended for completely different things such as „allow CircleCI access to my Gitlab repositories“.
Is it really worth investing in OAuth2 these days just because Auth0 pours millions in marketing? I highly question it…
- mooreds 5y ago> Is it really worth investing in OAuth2 these days just because Auth0 pours millions in marketing? I highly question it… I don't know your exact use case. But I did a presentation about OAuth in the real world for Denver Startup Week and there was a slide about why you should use OAuth. * Standards based * Sharp security minds designed it * Lots of edge cases handled * Interoperable * Not perfect, but far better than if you aren't using Oauth * Isolates sensitive user data like passwords or PII into a single server. Enforces separation of concerns and allows for single view of user (this benefit is not exclusive to OAuth, of course, but if you chose OAuth, you get it). Disclosure: I work for FusionAuth, an auth service provider.
- theakirati 5y agoTo piggyback off of Dan, I'd also mention that there's a few other benefits of using OAuth. OAuth allows allows you to delegate all sorts of auth features to an external IdP, instead of handling them yourself like: * Password management * SSO * A bunch of other features and security (MFA, Forgot password, breached passwords, brute force, password validation, threat detection, account takeover protection, etc.) Another benefit of OAuth is once you use the OAuth authorization code grant in your app, you can swap out IdPs. So, that delegation pattern is really helpful for offloading the extra work of building Auth, and it can "plug and play" into any IdP that supports it. At the end of the day, OAuth is the protocol that lets you delegate all the auth code to an external auth provider, instead of trying to build it all yourself.
- theakirati 5y agoHey vexcaustic, author of the article here. I agree, sometimes implementing OAuth2 can be rough. We promote it at FusionAuth because OAuth2 is standardized and secure, and has been tested in lots of different scenarios. I took a look at kratos, it looks sweet, thanks for the link. We've had some FusionAuth users use Ory OathKeeper with FusionAuth too. It is interesting to see the different solutions for user management and login security that are being developed.