4 ms·
I’ve been in this situation before. I had a full dev team, we had a security architect assigned to us. We needed to do a pen test regardless of it we used a fra
by diroussel 4y ago
I’ve been in this situation before. I had a full dev team, we had a security architect assigned to us. We needed to do a pen test regardless of it we used a framework or wrote it from scratch.
Our requirements were quite unique and so writing custom code but aligning to an OIDC style flow was a good choice for us.
In the end it was a good choice and much easier than forcing an auth framework to do something it wasn’t designed to do.
- mooreds 4y agoCan you tell us anything about the unique requirements? I'd love to learn more.
- diroussel 4y agoWe wanted to deploy into AWS lamba (using nextjs) with the main login flow being outside the app, then token validation being in a edge lambda. This decoupled the app from the authentication , we didn’t need any any authorisation.