4 ms·
I do think it's pretty amazing that a basic modern authorization system essential has a hard dependency on a 20+ million lines of code web browser, even for nat
by anderspitman 3y ago
I do think it's pretty amazing that a basic modern authorization system essential has a hard dependency on a 20+ million lines of code web browser, even for native apps. And mostly just because we need a central location to store auth cookies. I'd love to see a stripped-down "auth browser" that has no job other than rendering basic style-free forms (maybe even declared in JSON) and storing cookies. Problem is you have to get the big boys to stop requiring JavaScript for their auth flows.
That said, after doing a decent amount of implementing OAuth2/OpenID Connect, the core profiles are actually pretty reasonable and about what you would want to do if you were starting from scratch. The trick is making sense of all the optional stuff. There have been some efforts[0] to improve that.
The part I've never been able to figure out is why does OAuth2 use tokens at all, rather than generating a key pair and sending the public key with the initial auth request, then signing subsequent requests?
[0]: https://fusionauth.io/articles/oauth/differences-between-oauth-2-oauth-2-1 https://fusionauth.io/articles/oauth/differences-between-oau...
- Solvency 3y agoWhat's the super Birds Eye view tldr reason that such a thing does require 20 million lines of code? How did this happen?
- flashback2199 3y agoI don't think OIDC requires a browser.
- anderspitman 3y agoI would be very interested to see an implementation that doesn't. And I'm not being sarcastic. Even the device flow has you open a browser on another device.
- pugz 3y agoI guess it depends on what we meant when we talk about OIDC, but in system-to-system authentication (e.g. GitHub Actions to ${cloud provider}), there are no browsers involved. But that's a fairly different use-case that happens to be under the OIDC umbrella. https://docs.github.com/en/actions/deployment/security-hardening-your-deployments/about-security-hardening-with-openid-connect https://docs.github.com/en/actions/deployment/security-harde...
- fireflash38 3y agoBasically just resource owner/password flow. Because clearly programmers don't know how to handle sensitive information, only browsers can.
- anderspitman 3y agoI think it mostly just evolved that way. OAuth started on the web and if you're using a browser anyway you might as well take advantage of HTML/JS rendering for the UI and cookies for secure storage.
- alexvoda 3y agohttps://player.vimeo.com/video/52882780 https://player.vimeo.com/video/52882780
- EGreg 3y agoWell I saw this the other day https://m.youtube.com/watch?v=kZRE7HIO3vk https://m.youtube.com/watch?v=kZRE7HIO3vk
- LastTrain 3y agoBecause everyone already has it installed.