2 ms·
> The general consensus among web developers seems to be to just let a third party do it. Outside of personal projects, third-party auth providers must be audi
by johncoltrane 1y ago
> The general consensus among web developers seems to be to just let a third party do it.
Outside of personal projects, third-party auth providers must be audited (think GDPR or PIPL), budget must be allowed, contracts signed, etc. so web developers rarely, if ever, have their say on the matter. The decision is taken long before anyone wrote a single line of code. From a project management perspective, it's an easy trade-off to make: one sprint for integrating Okta versus who knows how many for badly implementing something that requires a level of expertise that no one on the team has reached.
For personal projects, the trade-off is a bit different. Resources are scarce so, even if implementing auth is actually not very complicated(1) and can even be quite fun, there are probably more immediately interesting things to do. So you integrate a third-party solution in a wednesday night and you move on.
[1] https://thecopenhagenbook.com/ https://thecopenhagenbook.com/