4 ms·
I really wish directus had a simple "cookie" based auth, and not all this crazyness with a cookie + refresh token + renewals + refresh + JWTs +... I was trying
by likortera 4y ago
I really wish directus had a simple "cookie" based auth, and not all this crazyness with a cookie + refresh token + renewals + refresh + JWTs +... I was trying to use it with Next.js, where I needed to authenticate the current user server side to fetch some data and it was by far the most overcomplicated part of my application.
We ended up switching to Django, where just an traditional http only secure cookie which we "proxied" from Next.js to the frontend and back was enough and maybe even more secure than all the mangling we had to do with the refresh tokens, etc.
I really wish this trend of fancy authentication mechanisms goes away. It doesn't take in account how easy they make for people to mess up on their implementation/usage of it when things are too complex.
- d1sxeyes 4y agoI feel you there - I do always feel like I'm writing a lot of code for something that should be better abstracted away - if I send a u/n and p/w once, then I should be logged in until I log out (or my session is invalidated server-side), and I'm always worried that that doesn't happen properly when I use the SDK. I THINK it does, but I got burned once when it broke last year around the 9.0.0 update, and now I struggle to trust it... I tend to end up doing something like this: https://github.com/directus/directus/discussions/10101 https://github.com/directus/directus/discussions/10101
- likortera 4y agoYeah, that's the point. I think the SDK is not that helpful when running code in the backend (SSR). What frustrates me is that I don't get what's wrong with just using the traditional http-only secure cookie backed by a server side session. That just works, and it's one of the most safe ways to do it. Even banks do it that way. All the JWT temporary refresh token whatever sounds like somebody was just bored and wanted to have fun. Sorry, I was pretty burned out about this. So much that we ended up swapping it for something else.