3 ms·
I think the main argument usually is time savings. Personally I just always do E-Mail and password auth, yea its old and not the shiny new thing, but it doesn't
by sevenzero 5mo ago
I think the main argument usually is time savings. Personally I just always do E-Mail and password auth, yea its old and not the shiny new thing, but it doesn't require me to integrate 200 different ways of doing auth.
We should be able to demand users remembering their passwords, I dont like to cater towards users who simply dont want to put in the work to use my product.
Will I lose potential users over this? Yes. Does it feel bad knowing I am in control and wont have to offload to 3rd party vendors? Hell no.
- sreekanth850 5mo agoSame here, Just email + password, no google dependency initially. If more users ask we will think of it. but again you don't need a cloud vendor for all this.
- dotancohen 5mo agoThat's great for B2C, but B2B demands SSO.
- sevenzero 5mo agoNot really, we do B2B. E-mail & password is good enough for our customers. They really really dont care about what kinda auth we use.
- Orygin 5mo agoGreat for you but that's not the case for a lot of B2B contracts we have. A lot of them require integrating with their SSO, not just for login but for permissions too
- sevenzero 5mo agoDo permissions follow the same model everywhere with SSO or do you now have to set up permission logic everywhere for new customers? Like company A uses "admin" as role while company B uses "management" for essentially the same role?
- williamdclt 5mo agoDepends on your industry I guess. My personal experience is that small-to-medium companies ask for SSO, large and enterprise _require_ it.
- zarzavat 5mo agoYou do you but most businesses if given the option between supporting OAuth to reduce friction on signups, or only supporting password auth, will choose the option that makes them more money. You don't have to use a 3rd party service for OAuth. You can do it in house.
- sevenzero 5mo agoYea I know, I just don't want my app to have a google logo on it, or whatever other companies people use to login with. E-mail and password will forever be my go to solution. I want intentional users not the ones that click "sign up with google", try out the app once and never come back. Also I don't have the time to learn how to properly integrate more auth methods into my app. I want my own user table, I want predictability on how a user model looks and I want to be in control of everything.