3 ms·
The final problem is that not many people will write a full implementation of it other than the big players like mozilla itself or Google or Microsoft. An
by PythonicAlpha 12y ago
The final problem is that not many people will write a full implementation of
it other than the big players like mozilla itself or Google or Microsoft.
And the latter two don't have a ton of incentive to do so.
When I see such a proliferation (I looked at one architecture image of OpenID.connect and was shocked) than I am reminded of SOAP and I again think, that one reason might be, to hold smaller players at bay -- and to give the bigger players an advantage. For Facebook, Amazon or an other big internet company, it is really easy to even implement a big stack of software with complicated architectures and many features -- but for a four people start-up it is a big problem.
- vertex-four 12y agoHonestly, if you already have a working OAuth2 server implementation, adding OpenID Connect support to it is not difficult. For oauth2-server-php, the OpenID Connect extension is a few hundred lines. On the client side, there's a glut of OpenID Connect implementations for various languages, or you could outsource it to the likes of mod_auth_openidc for Apache, or a node.js proxy using Passport, or whatever you'd like. Once a user is authenticated, which can be handled by the libraries just fine, the rest of the data model is simply OAuth2 and a key/value list of claims about the user. I'm not sure how anything is pushing smaller players out, so long as those players are willing to use MIT (or equivalent) licensed code?