7 ms·
OAuth for all
- gnabgib 3mo agoTitle: Unlocking the Cloudflare app ecosystem with OAuth for all
- asdf88990 3mo agoCloudflare turning into a Cloud platform is undoing what it was really doing well: making small clouds and diy hosting manageable in the hostile web environment. Once their revenue from Cloud services overtakes their core offering, bye bye Cloudflare free and so on.
- reed1234 3mo agoI doubt it. It’s cheap to run and a good funnel
- weird-eye-issue 3mo ago> Once their revenue from Cloud services overtakes their core offering, bye bye Cloudflare free and so on. Wait so what do you think their core offering is?
- asdfsa32 3mo agoDDoS Protection?
- 3997531578 3mo ago[dead]
- weird-eye-issue 3mo agoBy proxying through their Cloud?
- asdf88990 3mo agoCloud has a specific meaning, it doesn’t mean anything computer.
- kordlessagain 3mo agoMan-in-the-middle everything.
- rozenmd 3mo agoCloudflare free is the business model: https://blog.cloudflare.com/cloudflares-commitment-to-free/ https://blog.cloudflare.com/cloudflares-commitment-to-free/
- asdfsa32 3mo agoIf you carefully read the article, it just explain how it is an economic decision, and one which sooner or later will be no longer the case once they can capitalise on with anything above free, which is the lowest of the lowest bars. But even to entertain this is crazy, not because of decades of history of capitalist and market enterprise in general, but very specific cases of Technology Companies starting with these kind of feel good ideas and declaring "Don't be evil" or things like " access, safety, and shared prosperity" as their core ideals, turn into absolute panopticon and collaborate with unjust killing of women and children in less than a decade. The market isn't for free.
- NicoJuicy 3mo agoYou don't know Cloudflare? Their first products were production grade examples of the SDN that required a lot of bandwidth (DDOS/CDN). The cloud is a logical continuation. Their business was always the "internet", see their ticker => NET. Dev free is part of the marketing cost and would stay under the current leadership.
- sandeepkd 3mo agoNot sure whats the play here, there is no world where this can turn out good. Cloudflare is more or less infrastructure provider, this idea of some user delegating permissions to their account to some third party client for infrastructure is ripe for abuses. If companies like AWS are not doing it then its for a good reason.
- codebje 3mo agoHow different is this to, eg, the Google developer program, in which I can create a new OAuth client for Google users?
- sandeepkd 3mo agoOAuth2, to be more precise, is a protocol which can be used both for authentication (verifying the user) and authorization (accessing resources on behalf of that user). Most people in CIAM (customer identity, individuals owing their account instead of representing a company) only interact with OAuth client for authentication. They do not give access of their google account to some THIRD PARTY COMPANY.
- smw 3mo agoSure they do. All the time! For example, if you want to use a script in Google Docs these days, you have to go through an oauth flow to give that script's app permission to do certain actions in your Docs.
- ok_dad 3mo agoDo you understand what OAuth is? It’s like an API key but less likely to be abused. This is a good thing. It helps security in many ways and makes security flows more safe than carrying around a token.
- usr1106 3mo agoMaybe he doesn't. And I know that I don't (at least not in depth). And that's the frightening thing here. Using a protocol that many don't understand for access to valuable resources
- xyzzy_plugh 3mo agoThis is such a weird blog post. It's full of technical details, but I'm really not sure who they're for. There's nothing particularly novel or impressive. If anything the fact that it took them this long should be embarrassing. They pad it out with a table of stats that are just kind of meh? Congrats I guess for releasing something without burning the house down? As an on-and-off customer of theirs I tried to quickly skim for some of the details that would impact me, the theoretical end-user, but the vast majority of TFA is just about how they pulled off this apparent feat of engineering. I'm not trying to be pessimistic, and I don't fault the author (but I question the culture). I honestly don't get who this is for. For the record this is something they should have had... at least six or seven years ago?
- parsadotsh 3mo agoI for one appreciate them sharing this and found it a very interesting read. Many of us don't have experiences at companies at this scale and so it's nice whenever I get to read about what happens behind the scene.
- xyzzy_plugh 3mo agoUsually I expect an eng blog post to be a recruitment vehicle, wherein the authors articulate a really hard problem they solved, or some novel approach they took, or the cool new open source project they released (for their future SaaS play). But this is so mundane it bothers me in a way I find surprising. It's more about how they made some questionable choices in the past and how they finally paid off that technical debt. Is it interesting? Perhaps I am just getting old and jaded. What I find odd is how light TFA is on actual details as to what it is they shipped. This is the kind of thing I'd ship internally to the org as part of a weekly update or something, but not what I'd expect on a public-facing corporate blog.
- system2 3mo agoI hope Cloudflare does not turn into Google, with so many different things that they will eventually kill all of these services randomly because of the maintenance cost.
- holistio 3mo agoI still kind of think of Cloudflare as "big ass CDN". I can't keep track of all the new things they do. Something-something-R2? Maybe?
- zaptheimpaler 3mo agoOauth and enterprise auth has to be the worst thing ever made, it might be the most confusing and frustrating part of dealing with the cloud. Even the AI tools took a year to just get basic Oauth working on headless systems without assuming you could open a browser. If they're going to go down the auth rabbit hole with RBAC/IAM/Workload identities?/service accounts and all the trash the big cloud providers have, I just hope to god they leave in the simple shit for personal use. I just want a damn API key, I keep it a secret and revoke if necessary and don't need 10000 layers of auth bullshit tangled up in every layer of every platform.
- jurgenaut23 3mo agoI am tempted to agree with you because I could never quite wrap up my head around it, but I never had to implement OAuth beyond a brief skim through the doc for my own understanding. I always thought this complexity was there for some good reason (security?).
- messe 3mo ago> was there for some good reason (security?). To cover the myriad of (sometimes downright stupid) requirements that large enterprises have.
- iririririr 3mo agofar from it! it was just designed by comitee who both future proofed it and made sure it worked on low powered devices from 1971. i make a point to implement oauth from scratch, because using the overly complex libraries expose you to bugs such as attacker sending a token which the metadata just says "no encryption or signature. trust me bro", which is actually part of the spec if you combine some options. while in the real world, if google or apple sends you a token that is not always the same signature cypher (one of a dozen by the spec) you are better of threating as malicious, because it pretty much is. a manual implementation of a token consumer is about 20 lines... including downloading the provider keys and checking it (which most startups never do! allowing anyone to just sign a token as anyone)
- fmbb 3mo ago
- necovek 3mo agoI thought I understood what Oauth was (a standardized protocol to provide per-client access keys), but this article confuses me. What's a "self-managed" Oauth here? What is access is being granted to, who are the clients, who are the partners...? Anyone care to elaborate?
- Groxx 3mo ago>Earlier this month, we announced self-managed OAuth, making it easier for customers to create and manage their own OAuth clients for delegated access to the Cloudflare API. They're letting you host an OAuth system to approve/deny access to your own resources, so you can build whatever logic you like, rather than waiting on them to allow you to do X under Y conditions. Essentially "log into CloudFlare" -> CF sees you're using this self-managed OAuth -> redirect to your OAuth -> CF trusts your response, and approves access to your account if you approve access.
- niyikiza 3mo agoMeans you can basically host your own AS
- Exoristos 3mo agoYou'd think implementing OAuth2 were splitting the atom the way so many dev teams won't even consider rolling their own or using the multiple well-tested free libraries.
- iririririr 3mo agothe end game: they will start requiring proof of id to access resources they host. probably getting ahead of something the UK and some us states will require soon, as they already require from the sites behind cloudflare.
- utopiah 3mo agoClassic Cloudflare, for all, works well, not too expensive... but, and consequently of all those positive attributes, positioning itself at the center of everything.
- swyx 3mo agoi mean. fair trade?
- utopiah 3mo agoIt's a good move for them but it's problematic for anybody who cares about a decentralized Internet.
- vachina 3mo agoMy policy has been, I make sure I have an equivalent self hosted solution that I can immediately switch to, before deploying said feature to Cloudflare. That said I only use cloudflare for piping and none of the compute stuff.
- utopiah 3mo agoIndeed, a self-hosted compatible fallback is a great failsafe.
- enraged_camel 3mo agoI hate to say it, but I think the ship of decentralized Internet sailed a long time ago, and it's not coming back.
- shimman 3mo agoNo, consolidation within the tech industry has never been good for workers or open source development. For someone who considers themselves as part of the open source community I've been extremely disappointed how anti-worker and pro-corporation you come across. Don't worry you aren't unique in this regard, many other nonworking dev influencers say similar things: never championing for workers but somehow always championing positions that help investors + corporations first and foremost
- fithisux 3mo agoCloudflare to cut about 20% of its workforce https://news.ycombinator.com/item?id=48054423 https://news.ycombinator.com/item?id=48054423
- rcarmo 3mo agoNice, but as usual if you want a 3-step “getting started” example you have to wade through the docs, and even then…
- firasd 3mo ago[dead]
- aeneas_ory 3mo agoAuthor of Ory Hydra here! Very cool to see this blog post and technical description! I never would have thought this piece of software would secure the internet companies in the world :) Also great to see that the 2.x version performs so well for you! The CPU use is ridiculously small for that scale! We have a commercial variant that‘s even faster, if you ever run into trouble. If anyone here is interested in providing their own oauth, IAM, rebac permissions, API keys, agent security - check out our open source & commercial products at https://github.com/ory https://github.com/ory and https://www.ory.com/ https://www.ory.com/
- hiimshort 3mo agoJust a passerby, but wanted to say thanks for your work. Ory services are a delight and I was excited to see them spring up years ago and even more excited to see them continue to be developed and put to good use!
- aeneas_ory 3mo agoTruly appreciated, thank you :)
- caseyf 3mo agothank u for Hydra, its great!
- adeptima 3mo agoappreciate all your work Hydra, Kratos and my favorite small RBAC lib - ory/ladon
- Avery29 3mo agoOAuth is great when you actually need user delegation. For simple server-to-server API access, scoped keys with rotation, audit logs, and fast revocation are often a much better developer experience.
- firasd 3mo agoThis is basically about OAuth for accessing a Cloudflare account, not a CF-hosted generic 'Login' type stuff for custom apps
- dmux 3mo agoYeah, I was originally thinking of the latter and generally interested as to what they were providing.
- miguelspizza 3mo agoWhat’s ironic about this is they technically already shipped a looser version. The entire cf api is exposed as an MCP server which supports OAuth and dynamic client registration. Not sure why they don’t just support DCR or CIMD for this too
- kjgkjhfkjf 3mo agoI wish Cloudflare provided a paved path for user auth. Better Auth seems to be the most common recommendation for Typescript applications, but there currently doesn't seem to be an official integration with Workers either from Better Auth or from Cloudflare. I currently use Supabase to avoid having to set up my own user auth on Workers, but I would much prefer to use D1 etc.
- sarreph 3mo agoI’ve done it in one of my projects here using Drizzle, and it’s worked fine in testing so far. https://github.com/rorz/manual.email/blob/main/packages/db/src/auth-schema.ts https://github.com/rorz/manual.email/blob/main/packages/db/s...
- notpushkin 3mo agoAs much as I’d like to love Better Auth, the assumptions they make sometimes are so damn annoying. Having to resort to hacks to e.g. support an OIDC provider that doesn’t return user’s email (like Telegram) is a PITA. I find Lucia Auth’s approach more useful in the long run – you have some boilerplate living on your codebase but you own it completely and it doesn’t try to make decisions for you: https://lucia-auth.com/ https://lucia-auth.com/ --- That said, why don’t you use Better Auth with Drizzle and the D1 adapter?
- v5v3 3mo ago"Ory Enterprise License: Unlock enterprise-grade features like security SLAs for CVEs, SAML, B2B organizations, multi-tenancy, and better scalability." [0] Or just stick with KeyCloak that offers a full self hosted product... [1] [0]https://github.com/ory https://github.com/ory [1]https://www.keycloak.org/ https://www.keycloak.org/
- aeneas_ory 3mo agoKeyCloak is great if you want a full stack Java server to run internal workforce for example, but Ory is much better at running high scale (eg at OpenAI https://www.ory.com/case-studies/openai https://www.ory.com/case-studies/openai) and in a composable fashion. Yes we have an commercial version because how else can one finance world class open source powering the biggest software names on the planet? It‘s a good thing that Ory has a business model that works, not a bad thing. And by the way, IBM finds ways to charge you for KeyCloak too ;)
- khurs 3mo agoValid points (although Keycloak was Redhat not IBM and then donated by them to CNCF), but should "security SLAs for CVEs" be listed as a premium feature? Looked at the case study, uses Cockroach which is now commercial, so potentially with the dual costs of Ory and Cockroach licenses, unless you need massive scale, would be too expensive for small/medium and also startups? Unless your sole focus is on enterprises? And Keycloak also has such a implementation https://www.cockroachlabs.com/blog/deploying-keycloak-on-cockroachdb-with-phase-two/ https://www.cockroachlabs.com/blog/deploying-keycloak-on-coc...
- aeneas_ory 3mo agoMy mistake - I thought it‘s now just under the IBM corp but it is indeed in CNCF. Still, IBM offers a commercial product around KeyCloak. If you serve 900m weekly active users, you need this type of distributed database architecture that is expensive to run. But at that point the cost of running it is a fraction of overall infra spend. No start up really needs this level of scale, only Enterprises (hence it‘s gated). Making Cockroach work is more work than just wiring up the SQL, you actually need to deal with it like dynamodb under the hood and use primary keys efficiently, avoid hotspots, and all that jazz. Most companies (like Cloudflare!) do just fine with Postgres and one of our services. Ory Hydra is written in Go, doesn’t need JVM, very little RAM, doesn’t need caches or start up time due to cold starts. The architecture is different and that makes it cheap and fast to run. From the blog post - they run Hydra on 0.6 vCPU and 200MB of RAM. That’s probably as cheap as it gets! It‘s a different tool for a different problem than KeyCloak - both have their place.
- CommonGuy 3mo agoCloudflare really likes to publish new projects, but improving them in the future is not really their style. Some examples: - They launched Cloudflare Web Analytics in 2020, but it still does not support basic things such as UTM parameters or custom events - With wrangler (their CLI), you still cannot undeploy a Cloudflare Page
- r3trohack3r 3mo agoThe last commit to wrangler was 2 hours ago? https://github.com/cloudflare/workers-sdk/tree/main/packages/wrangler https://github.com/cloudflare/workers-sdk/tree/main/packages...
- aroman 3mo agoThat’s exactly the point. Wrangler, being cloudflare’s primary CLI tool, is a microcosm of exactly the problem GP was articulating: it’s focused way more on adding new commands than improving existing ones. Many products, even supposedly “GA” ones, still lack basic operability via wrangler because instead of finishing building out its capabilities to manage existing services, they prioritized adding rudimentary support for new ones.
- carimura 3mo agoI suspect CF is their future CLI.
- dust-jacket 3mo agoNah, you don't get to claim they don't work on improving their products, and then handwave away actual updates to it with "yeah but those aren't the improvements I wanted". That's just life and priorities. Abandoning something, and not making the changes you want to see are entirely different things.
- dumah 3mo agoSure he does. It's not handwaving to complain that shipped features are never completed and a functional CLI for fundamental and critical tasks is never delivered.
- littlecranky67 3mo agoMy pet peeve is the standard OpenID connect implementation of OAuth for SPAs - which will probably use the PKCE code flow. It is probably for historic reasons and old browser compat, but exposing access token and revocation token to javascript is IMHO just madness. In modern security flows you would save those tokens into cookies that are HttpOnly and SameSite=strict and prevent a myriad of JS based attack vectors.
- zeafoamrun 3mo agoGood thing they're laying off more of their workforce to support these new products https://app.dealroom.co/news/feed/cloudflare-ceo-warns-ai-driven-mass-layoffs-coming-in-next-6-12-months-after-cutting-20-of-workforce https://app.dealroom.co/news/feed/cloudflare-ceo-warns-ai-dr...
- s_kazmi 3mo agoI have shifted all my apps backend as much as possible to cloudflare. Get my domains from it, all security stuff. hosting, etc Love em., greatest tech company of all time. One stop shop.
- khalic 3mo agoCan't wait to have half the internet's auth sessions die because of an outage
- ALLTaken 3mo ago[dead]
- hmokiguess 3mo agoI used to manage a self hosted instance of the identity server framework for dotnet that ran several billions of requests per month, my experience managing OAuth and OpenID Connect at that scale was that it was pretty much a solved problem with relatively low maintenance *(it was a critical core service at our org, with heavy compliance, but our team was maybe 3 people taking care of it? it is still up and well to this day)* I could never understand why there were so much confusion spread around this protocol, almost every junior engineer I worked with would just struggle grasping it, I cannot recommend Scott Brady's blog enough on the topic https://www.scottbrady.io/ https://www.scottbrady.io/ it was illuminating to me I think there's an essential primitive "fear" whenever authN/Z is involved that creates friction for most engineers, they're used to problem solving and this fits within a pre-condition to your problem solving so there's a cognitive tax or something around it
- littlecranky67 3mo agoIs that the identity server for dotnet that has been converted into a commercial product and costs a huge pile of money to use (lite starts at almost 6000$ per year): https://duendesoftware.com/pricing https://duendesoftware.com/pricing
- hmokiguess 3mo agoYes, we started using it on version 3 and ejected from it with self hosting prior to it becoming a commercial product.
- littlecranky67 3mo agoAnd who provides the security patches for it now?
- hmokiguess 3mo agothe same internal team, on the things that have drifted since then
- isabellehue 3mo ago[flagged]
- throwaway613746 3mo ago[dead]
- aberrahmane_b 3mo ago[flagged]
- adeptima 3mo agoMixed fealings cause the full context should include plans on both Authorization and Authentication flows at least withing Cloudflare ecosystem. No github examples Anyway good start in the right direction from Cloudflare, yet still long way to go especially compare to the full Ory's offering its built on. Ory's Kratos handles identity, login, registration, recovery, MFA... https://github.com/ory https://github.com/ory IMHO full scope should include plans on user store, SAML, multi-tenant org model. Good example - Zitadel https://github.com/zitadel https://github.com/zitadel has managed UI for orgs multitenancy, OIDC/PKCE supports, etc you can even partial glue RBAC to it Subabase offers managed and opensource https://github.com/supabase/auth https://github.com/supabase/auth Siding "MCP is dead, Skills forever" what bother me about all of them is planning to plug MCPs and rotate keys ... this start hitting the fan very soon OAuth 2.0 Dynamic Client Registration (RFC 7591) https://datatracker.ietf.org/doc/html/rfc7591 https://datatracker.ietf.org/doc/html/rfc7591 https://modelcontextprotocol.io/specification/2025-03-26/basic/authorization https://modelcontextprotocol.io/specification/2025-03-26/bas... Any comments greatly appreciated. Especially in multitenant saas and built-in "AI assistants" context
- avemg 3mo agoHaving recently gone through this exercise with our IAM vendor to secure our MCP service, OAuth DCR scares me in that context. With redirect flows, which are usually what you're using when you're plugging your MCP into an agent, the spec says nothing about how to secure that. I really don't want to allow just anybody to register a client with an arbitrary callback. That's opening us up to phishing. Register your client with a malicious callback url and then trick users into clicking a link that initiates that flow. Our legitimate idp will authenticate them and then send then hand their access tokens off to an attacker. The spec handwaves around this talking about initial access tokens which a client would obtain first in order to register but the details are sparse and probably unworkable when we're talking about every end user being a client. Ideally i would be able to specify an allowlist of redirect patterns so i could limit it to say, chatgpt or whatever else. But that would be a non-standard behavior so my IAM vendor isn't in a hurry to do it.
- adeptima 3mo ago
- dizhn 3mo agoThe post says this is Hydra based. Authentik has been listing CF as a customer for a while now. I thought the new announcement might have something to do with that but down look like it.
- zvolsky 3mo agoHey, Grant here - I wrote most of the 2.0 migration code together with Aeneas. Thank you for the writeup team Cloudflare! > After investigation, we discovered that there was an issue in one of the Hydra migrations that corrupted the state of certain valid OAuth sessions, which resulted in the migration marking them as invalid. Was this one of the open source migration files? While I'm no longer involved in the project, I'd be curious to know if it's been addressed upstream.
- nemoniac 3mo agoCan anyone recommend a straightforward, open-source OAUTH solution to self-host. Ideally I would like to be able to ask a user for their Google/Microsoft/Apple email address and just drop it into a config file for authorization. The user then autenticates themselves at their G/M/A Id server and gets access. Or is this too simplistic?