4 ms·
I argue that the complexity you are describing is inherent in any solution where multi-level sessions are present-- whether the auth mechanisms is OIDC, SAML, o
by jonbake 3y ago
I argue that the complexity you are describing is inherent in any solution where multi-level sessions are present-- whether the auth mechanisms is OIDC, SAML, or something bespoke. Beyond social logins, there are use cases where multi-level sessions are required. One example is delegating authentication to another IdP. It's possible to use a OIDC client and configure the IdP to not create a session if multi-level sessions are not required.
- kjuulh 3y agoFully agree if you need the session. Then yeah some kind of delegation/abstraction is required. Especially for social/3rd party login. The missed I've seen is simple that oidc was used on multiple levels to facilitate a login flow and the sessions discarded afterwards