4 ms·
I've used this lib in a few MVPs and it was easy to use if you do things their way (which wasn't that big of a deal for an MVP). > The functionality provided f
by muratsu 4y ago
I've used this lib in a few MVPs and it was easy to use if you do things their way (which wasn't that big of a deal for an MVP).
> The functionality provided for credentials based authentication is intentionally limited to discourage use of passwords due to the inherent security risks associated with them and the additional complexity associated with supporting usernames and passwords.
I have to admit while as a dev I sympathize with this stance, as an end-user I really hate it. I pay for a pwd manager and feel much better about using a user+pwd combo. I get that oauth is more secure in general but somehow I feel uneasy to give access (even limited) to my personal gmail or github.
- DrewADesign 4y agoAgreed. I'm a bit more privacy-focused than most but oauth + 3rd party seems like solution that should solve a specific problem or enfranchise a specific group of users and always have a password-based alternative. It's probably futile, but I'm just not particularly enamored with the idea of openly inviting all of those big companies and their greedy telemetry vacuums into every little last corner of my life.
- satvikpendem 4y agoWhat about a passwordless / magic link to your email? I've found that to be the best option as a dev/user, since no passwords necessary, no lock-in ("which OAuth2 provider did I use for this account, Google, Apple, GitHub, or Facebook?"), and it works decently well on all devices.
- muratsu 4y agoI forgot the exact issue but if I recall it correctly, pwdless sessions are meant to be short lived sessions. I equally dislike reauthenticating my sessions every day
- satvikpendem 4y agoWhy would they be short-lived? Just send a refresh and access token like normal authentication, the only thing you're changing is whether the user authenticates from a password versus a link which has a unique identifier, they're both looked up from the database / in-memory cache all the same.
- NegativeLatency 4y agoAs someone with ADD I really prefer not to have to bounce through my email client to login. (I prefer passwords to other current options) Webauthn looks great though, really looking forward to that taking off
- satvikpendem 4y agoI agree, however check out the Checker Plus extension for Gmail (if you have Gmail). I never open up Gmail anymore, I can access all my emails through the extension which pops up a customized email window. On the phone, for example with Slack, it has a button like "Open email" which I click, and then it opens the email, then I click the link which takes me back to the app, works pretty well.
- jiveturkey 4y agooauth doesn’t in any way give access to your gmail or github, not when used in an oidc or oidc-like flow