3 ms·
It's one of the many reasons we have the saying, "Don't roll your own crypto. I remember when this saying referred to people rolling their own cryptography alg
by ern 2y ago
It's one of the many reasons we have the saying, "Don't roll your own crypto.
I remember when this saying referred to people rolling their own cryptography algorithms. When did it become about not doing your own auth? (I agree it's generally a bad idea, but curious about the scope expansion of the statement)
- tracker1 2y agoEven then, I don't think it's quite the same... I've built several authentication and authorization controls, for the past decade mostly around JWT, but even then, I find more of the formal dedicated systems are often more complex than a given application needs, but it does take some understanding in terms of what to get right and getting what things wrong can be problematic. You can use some tools off the shelf, but may want other bits to be custom. For example, I've worked on several applications where an external provider winds up sending the user through an adapter to the application itself. So that external roles or groups can map to application roles. Especially if your application may be Azure AD for one client, and Okta for another. And another still may want you to provide something (simple user/password backed).