Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ffo
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
11 ms
·
61.
▲
by
ffo
4y ago
Well you want to check your session cookies as well against something ;-) Surely you could trust a signature and lifetime but that makes the cookie no different than a JWT (only storage wise the differ in that case). Generally speaking it i
62.
▲
by
ffo
4y ago
This is so true in practice ;-) Also a problem I encountered in the wild, is that a potential attacker tries to trick a user into installing a malicious CA Public key as requirement to be allowed past the captive portal. Unfortunately mitig
63.
▲
Open Source Auth0 Alternative Built with Go and Angular Releases Version 2
(github.com)
8 points
by
ffo
4y ago
|
0 comments
64.
▲
Zitadel targets developers with open-source identity management platform
(venturebeat.com)
1 points
by
ffo
4y ago
|
0 comments
65.
▲
by
ffo
4y ago
I stand by my point that we openly disclose this and if you don’t want to share data either disable it or don‘t use it.
66.
▲
by
ffo
4y ago
I think we state transparently enough that we only report usage data and not your data within ZITADEL and you are free to disable it any time. If you don’t agree with this I recommend not using ZITADEL
67.
▲
by
ffo
4y ago
Thanks for the input. We definitely have SCIM2.0 on the radar. If someone feels intrigued we would happily accept a PR
68.
▲
by
ffo
4y ago
Only my own experience and secondary sources https://keycloak.discourse.group/t/maximum-limit-of-realms/8... https://stackoverflow.com/questions/54465114/when-realm-coun...
69.
▲
by
ffo
4y ago
I would love to chat with you guys. Hit me up with a mail florian(at)zitadel.com
70.
▲
by
ffo
4y ago
We know them ;-)
71.
▲
by
ffo
4y ago
From the IAM perspective (If the service is an IAM) I agree. But as SaaS provider I don’t want to use multiple realms because in that case my client would need to understand multiple issuers. Also Keycloak has a cutoff of around 400 ish rea
72.
▲
by
ffo
4y ago
Currently we provide a container image as well as K8s support. The v2 will allow us to extend our support to a plain binary as well as serverless containers (Knative et. al) Keycloak is a great tool but definitely not has B2B features like
73.
▲
by
ffo
4y ago
Haha or the good old netsend fun on school pcs ;-)
74.
▲
by
ffo
4y ago
Hm, interesting it need to check that ;-)
75.
▲
by
ffo
4y ago
Hi there First and most importantly, thank you for maintaining such a cool project with caddy! I use it all the time as nginx alternative (even though of being an nginx fan in the past). We do not directly support "forward auth" c
76.
▲
by
ffo
4y ago
We too ;-)
77.
▲
by
ffo
4y ago
Well thank you for your time. Let me check with the team. I am certain we can release 2.X with a Postgresql support ;-) I created an issue for further tracking https://github.com/zitadel/zitadel/issues/3598
78.
▲
by
ffo
4y ago
Will do ;-)
79.
▲
by
ffo
4y ago
Thank, we hear you! Currently we are discussing two things for this subject. 1) We think providing an embedded DB of some kind for easy to use cases with ZITADEL might be favourable to some of you (think Sqlite or an embedded CockroachDB )
80.
▲
by
ffo
4y ago
Thank you ;-) we will keep you posted.
81.
▲
by
ffo
4y ago
Thanks for the feedback. What do you not like of the new pricing? The pay-as-you-go approach? The background to this is, that we got many customers asking for features on the lower tiers and that many of them wanted to have a more linear sc
82.
▲
by
ffo
4y ago
Agreed, I mean that's why we built our solution completely open source in an open saas model and certified [1] our solution. We even provide our pentest results publicly, after mitigation of course [2]. The value we provide, when you a
83.
▲
by
ffo
4y ago
Love it, we will definitely create a post here in the next 2-4 weeks.
84.
▲
by
ffo
4y ago
True, we think that for most setups and early explorations K8s is too much of a beast. TBH we are in the process of switching our cloud from K8s to Cloud Run which is kind of close to Knative but without the ops hustle ;-)
85.
▲
by
ffo
4y ago
Thank you, v2 will be ready in the next 2-4 weeks. We are already running it internally ;-)
86.
▲
by
ffo
4y ago
Thank you too. Feel free to join our chat and ask questions any time https://zitadel.ch/chat (discord)
87.
▲
by
ffo
4y ago
Well to keep it brief, we see it the following way. Use: - ZITADEL: If you want turnkey solution built for the cloud with a great support for B2B, a strong audit trail and self-hosting, but also the option for SaaS - Ory: If you want flexi
88.
▲
by
ffo
4y ago
Maybe https://github.com/zitadel/zitadel could be an alternative to you. Its written in Go, can be self-hosted or used from a cloud service. It will also soon (end of May) provide SAML 2.0 support besides the current O
89.
▲
by
ffo
4y ago
You might want to have a look on zitadel [1] If you are intrigued into the differences, you can read some of them here [2] Oh and judging from your username: it could be interesting to you... because we use eventsourcing and cqrs ;-) Discla
90.
▲
by
ffo
5y ago
We will also extend the certification to more RP profiles and OP as well in the coming months
More ›