4 ms·
Related gripe: Your API doesn't always need OAuth. If I'm using your product as your customer and I directly want to leverage my own product data via your API t
by coderintherye 3y ago
Related gripe: Your API doesn't always need OAuth. If I'm using your product as your customer and I directly want to leverage my own product data via your API then I shouldn't be forced to have to implement [your almost invariably non-standard and difficult] OAuth implementation. An API key should be an option or HMAC if the extra security is felt to be warranted, but not the absurdity of needing to go through a client flow to check the boxes to say yes I consent to share my own data with my own self for this API use that will never be seen or used by a 3rd-party.
- paulddraper 3y ago> If I'm using your product as your customer and I directly want to leverage my own product data Correct. Fortunately, in my personal experience many services offer exactly this (JIRA, Hubspot, Slack). OAuth is only relevant where the resource owner and client are different parties. I.e. it's for third party clients, not second party clients.
- justrealist 3y agoNot to mention needing to create awkward shared service accounts to impersonate.
- lll-o-lll 3y agoOAuth client credential flow is this easy mode you ask for. It’s one call with a secret in it and back comes a token.
- sansnom 3y agoThe problem is "client credential" flow is not always available... And even if it were it might not as easy as you claim. In particular if you want to have an access token working on several instances. Most implementation allows only one access token at once so you need to have a shared storage and synchronization just for that... If you are developing an API please have mercy: provide something other than OAuth. For me, avoid OAuth unless there is 3 distinct parties.
- andix 3y agoIf you want to have password reset, OTP, 2FA, webauthn and so on, you probably want to use an external authentication provider. Integrating it with oidc/oauth is much easier, than doing all that stuff by yourself.
- TRiG_Ireland 3y agoI ran into that recently trying to connect a web shop we've built to an accounting platform. The web shop handles the entire checkout flow, but the owners also want a copy of the invoice stored in their accounting platform. The platform has an API. So our web shop can ping the accounting platform after an order is placed, and sent them a record of what was purchased? No. Because the API requires authorization. So the admin has to occasionally log into our website and hit a button to send invoices to the accounting platform. (At least we can send multiple invoices at once, so it doesn't require them to hit a button on each individual one.)
- joshxyz 3y agothis. im baffled how most platform that has user accounts does not allow provisioning of service accounts so users can easily access their data.