6 ms·
Congrats! It's nice to see that authentication and authorization are handled in the framework from day 1. This is often overlooked, but such a critical part of
by ogazitt 5y ago
Congrats! It's nice to see that authentication and authorization are handled in the framework from day 1. This is often overlooked, but such a critical part of building new applications.
- pistoriusp 5y agoThe auth package is a single interface that can be extended by 3rd party auth providers. When we originally created it we supported auth0 and magic.link, but now there are more 10! So, imagine you want something quick, so you pick magic.link and you launch to a bunch of demo user's, but decide it doesn't scale for your *new* needs, you'll be able to switch out to Auth0 without having to change any client side code (other than initialization). Of course you'll have to migrate your users. Having the ability to pick an auth provider, or host your own to suit your needs/ risk requirement, is very important to us!
- ogazitt 5y agoI love that design decision. How about authorization? :) disclaimer: I am a co-founder of Aserto [0], an authorization platform for developers. I think it would be awesome to explore how to grow the authorization model from a simple set of roles / permissions to a fine-grained model as the application matures. [0] https://www.aserto.com https://www.aserto.com
- pistoriusp 5y agoI am unfortunately no longer involved with RedwoodJS in terms of code, but it's open-source so anything's possible. I would reach out to David Price!