5 ms·
This is perfectly fine. Nothing to be ashamed of. At least you don’t need to create a logon form
by sdze 5y ago
This is perfectly fine. Nothing to be ashamed of.
At least you don’t need to create a logon form
- SavantIdiot 5y agoBut if you are rolling your own auth, you still need to create the signup, change password, reset password, confirm account, delete account, etc. pages. What's one more? Given that a logon form is >5% of the total amount of work to roll auth, seems kinda pointless to use this.
- Jolter 5y agoAuthor mentions internal tools, so I assume they already have a user database they integrate with on the back-end? LDAP or similar.
- amelius 5y agoBut still, why reinvent the wheel? There are plenty of libraries, even services available that do what you want.
- SavantIdiot 5y agoI recently re-rolled a password auth protocol because Auth0 and AWS Cognito were just so goddamn complicated. Ages ago I used stormpath because it was so simple, I realize there are many options today for federated logins, 2FA, SMS / phone password resets ... i just wanted an old-school password system for my dumbass personal site.
- jeofken 5y agoImplementing magic email sign in links is more straightforward and secure. You implement a login route which takes an email address. You symmetrically encrypt the email with a secret key from an environment variable, and send a link to /login?secret=<email-ciphertext>. This route handler checks that the ciphertect decrypts into the email, and if true, save the ciphertext as a cookie and check that it decrypts to the right email every time you require auth
- lukevp 5y agoSo anyone who compromised the cookie can login as this user forever? There’s no expiration or revocation in this protocol. Once you layer on expiration, this is basically sending someone a link with a JWT in the get request. Or you can hit the DB to check a secret key that’s in the email, and if it has expired, but this is worse than JWT because it requires a DB to verify the identity, where JWTs can be verified without interaction with the issuing system .
- deleted 5y ago[deleted]
- hnick 5y agoThis basically happened to me on a site, sans cookie. It sent notifications when customers left reviews. The convenient user experience is, when someone leaves a review, to forward the email with the review to the customer and ask how we can help. After doing this a few times I realised it had small links in the footer to login and administrate without a password, using tokenised links. Support had no way to expire these. I needed to create and migrate a new account (which incidentally ended up emailing hundreds of people for reviews they left months and years ago).
- jeofken 5y agoOh yeah of course you must do all those things! Assumed it was obvious that this was only about the steps leading up to giving the JWT token. Wrote it with one hand on my phone :-)
- zanny 5y agoI definitely think doing openid logins is way easier than any home rolled auth scheme. Delegate responsibility where you can, which includes use authentication. It sucks that Persona died all those years ago because web browsers really could use an identity system for users to authenticate themselves against sites with their browser accounts. The problem is then ofc getting browsers to cooperatively allow cross sign in. If messengers are anything to go by, siloed products really do not want to interoperate, particularly I imagine Edge and Safari.