6 ms·
I think that one of the most exciting facets of web3 stuff is around how easy it makes authentication and authorization scenarios. I've been working on a projec
by _gf4m 5y ago
I think that one of the most exciting facets of web3 stuff is around how easy it makes authentication and authorization scenarios. I've been working on a project that is an interactive NFT art project, where the interactive capabilities of the art are only possible for the owners of the piece. Providing authorization to the service is as simple as verifying ownership of the token. It's been pretty fun, I used an open source game engine as both the art generative tool as well as the interactive HTML5 app that allows for users to interact with their art.
That, and utilizing wallets as proof of identity, is so mindnumbingly simple compared to OAuth+OIDC for authentication and varying strategies for authorization. Granted the project is a small scale project, but with web3 architectural changes, it is empowering me to create a 2 person project (I am the only engineer too), that would be much more daunting of a project in traditional web architecture.
It's very exciting stuff, and I hope that people are able to see the tech for the possibilities it provides, especially when it comes to the NFT space. An NFT is just simply a single issue token, it can do whatever the developer wants, despite the common misperception being it is solely a link to a static image file on arweave / IPFS. Unfortunately the market is completely saturated with low-effort projects so it is very, very difficult to get eyes on innovative projects, but I hope that can change, and hope that I can create a project that allows even a small amount of people to see that there is so much more to the technology than what people have considered in 2021.
- Eflores 5y agoMaybe a curated marketplace would be a good place for those projects?
- shiohime 5y agoYeah, there are some marketplaces that are trying to only curate high quality projects, and others that are more open to accepting any project. It's actually pretty crazy right now, there's so many ongoing independent projects that some of these exchanges and launchpads have huge queues. I'm hoping that my project will be able to be featured on one of these marketplaces, but it's been rough out there. I think once I finish up and polish our roadmap and goals for the project, in addition to the already existing website and short video preview, we'll be able to get in on one of those. Fingers crossed, at least :)
- FractalHQ 5y agoWhat engine did you use?
- shiohime 5y agoGodot
- gz5 5y agoAgree. Gets lost in the decentralization memes? Strong, shared identity and auth for digital assets can't be overstated? This enables new models for digital ownership, value, trade, markets and storage of information.
- shiohime 5y agoI've been brainstorming a lot honestly about the implications that simple proof of identity and proof of ownership can really imply. I honestly might try my hand at creating a full out replacement for existing authorization techniques sometime next year, I've got some ideas and frankly if it works it's so simple it's stupid lol. It's so fascinating to me to realize that users being owners of their own private keys allows for us to create websites that don't rely on traditional registration flows, SSO, email addresses, password handling, or anything. It almost feels like cheating compared to the pain I've had to deal with in the corporate world implementing services like IdentityServer4 or Keycloak.
- outside1234 5y agoIs there a reference you could share for how you did authentication / authorization?
- shiohime 5y agoI unfortunately don't have an easily available reference really, it's all stuff I architected really myself. I can give a quick rundown though. For the authentication side: authentication, is simply connecting your wallet. Since each user has to have a wallet to interact with blockchain tech, that just simply means each user is the owner of their own private key. You can utilize this fact by connecting user's wallets. Once a user connects their wallet, you have proof of identity. If you need to verify it further, you can also have them sign a message and validate the signature on your backend. I've been working with Solana, and some of the wallet providers I've been integrating with (specifically Phantom wallet) have very easy to use APIs that allow for requests to sign a message. It uses Ed25519 for signing, so it is an incredibly quick operation to verify that the signed message is a legitimate message signed by the wallet they claim to be. You can even add something like a timestamp or whatever to the message, to avoid static message signatures phished from other sites. Once you have verified their identity by connecting their wallet, you can simply use these facts to retrieve whatever data they require. On the authorization side: I can really only use the example for my NFT project for authorization, but there are certainly many other ways to implement authorization. I have a service that I've created that I wanted to lock down to only be accessible to owners of a specific NFT. Since NFTs are essentially a proof of ownership concept natively, to provide access to my service I decided to implement the following: 1. Authenticate the user via connecting their wallet 2. Using the same signature method I mentioned above, sign a message, and verify the signature. 3. Once I have verified the user is who they claim to be, I check the token balance for the NFT that exists in their token account. Since NFTs are single issue, all I need to do is verify the user is holding the token they are attempting to use for accessing this service. For example, if a user X is attempting to access the service for token Y, it's as simple as: 1. Verify the user is who they say they are 2. Verify the user holds the token they claim to be holding. This is how I've been implementing authentication and authorization on my project. I think it's been really fun to architect this solution, we haven't gone live yet but I think that it'll work how I am expecting.
- themarmar 5y agoYup - love how easy it is to login to web3 projects! Have you also looked into Zero Knowledge? It lets someone prove that they know or have something without giving up any information about what they know or have. Not Boring did a good piece on it. https://www.notboring.co/p/zero-knowledge https://www.notboring.co/p/zero-knowledge
- JofArnold 5y agotldr: you can enjoy ZKPs without blockchain --- Adding to OP's comment a bit of context: As someone deep into ZKPs related to blockchain I should note that ZKPs have nothing to do with blockchain in their origin; the cryptography behind them was developed in the 80s (even protocols like zkSNARKs). Many applications are also not specific to blockchain and a lot of work on their mathematics does not relate directly to blockchain either That said, a decent chunk is now directly for applications in that field. For instance, key decisions around the cryptography used by Circom (a zkSNARK language) are predicated on the idea they will be used in EVM smart contracts. Same is true of snarkjs that exports Solidity verifiers.
- shiohime 5y agoI have not actually, I'll look into this, thank you for sharing!
- diveanon 5y agoTotally agree, built a few dapps this year and the auth story is always such a breeze. Had to work on an old project for a client that was using oauth2 and it felt so archaic.