Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
maxwellg
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
31.
▲
by
maxwellg
1y ago
Installing a dependency for myself is just and a little harder the first time. Asking every developer who will ever consume my service over CURL to install a dependency is absolutely an ongoing burden.
32.
▲
by
maxwellg
1y ago
Each JWT was passed as a query param over a 307 redirect from my service to the other side, so the JWT itself was the whole request to prevent tampering from the browser. It was for an internal tool that did one thing, did it well, and neve
33.
▲
by
maxwellg
1y ago
I _love_ JWTs for API authentication - one of the nicest APIs I ever consumed was essentially JSON RPC over JWTs. Unfortunately they represent a huge usability hit over API Keys for the average joe. Involving cryptography to sign a JWT per
34.
▲
by
maxwellg
1y ago
The Honeycomb MCP server has a similar tool call. How long until we get MCP support workflows and mixins as a standalone SaaS?
35.
▲
by
maxwellg
1y ago
It is very nice to get MCP support in ChatGPT. OpenAI really fumbled the bag with the OpenAPI-based Custom Actions (or was it Custom GPTs?). The web editor experience was always incredibly buggy, even months after initial release. MCP serve
36.
▲
by
maxwellg
1y ago
You're right that signing the token doesn't prevent login CSRF. Signatures protect against the second attack you mentioned. PKCE my favorite OAuth extension for preventing login CSRF as described. > In that case, the signature
37.
▲
by
maxwellg
1y ago
> Why does the ID Token have a signature? The ID Token can be passed from the Identity Provider to the Relying Party (RP) in a few ways. When `response_mode=id_token` is used, the ID Token can be passed in the front channel directly to
38.
▲
by
maxwellg
1y ago
Yep, if you put something on the open internet it needs authentication or it is public to everyone. This isn't a vulnerability unique to MCP - plenty of databases, REST APIs, S3 buckets, and other sorts of resources have been left open
39.
▲
by
maxwellg
1y ago
The usual tagline is that "OAuth is authorization, not authentication". OIDC is an authentication layer built on top of OAuth. This means that OIDC can be used for both authentication and authorization to a third party API - most
40.
▲
by
maxwellg
1y ago
These are all features of SCIM, not of SAML. SAML only communicates user metadata on login. SCIM can be used with both SAML and OIDC.
41.
▲
by
maxwellg
1y ago
On days I write code, I try to do one "cleanup" PR a day just to get myself warmed up. Sometimes it is removing a feature flag, sometimes it is rewriting a file to use some new standards like a better logger library or test patter
42.
▲
by
maxwellg
1y ago
This is the right move for Go. I have grown to really love Go error handling. I of course hated it when I was first introduced to the language - two things that changed that: - Reading the https://go.dev/blog/errors-are
43.
▲
by
maxwellg
1y ago
Oh absolutely - but the infrastructure required to support a "click link, get remote MCP URL added to config automatically" flow is _so_ much smaller than the infrastructure required for a "click link, download and install ar
44.
▲
by
maxwellg
1y ago
Ha! I love this. There's nothing like a proper Bash script to make me realize how terribly gross all of mine are. The drum I'm currently beating is that local MCP is a ton of fun for techies like us - if you're on this websit
45.
▲
by
maxwellg
1y ago
Ooh this is a favorite pet peeve of mine. HMAC is the better solution IMO but API Keys are so much easier for your customers to use: - API Keys are much, _much_ easier to use from the command line. CURL with HMAC is finicky at best and turn
46.
▲
by
maxwellg
1y ago
> When you add an MCP server to your Claude organization, you just add the MCP server. Each user will have to go through the integration's OAuth2 authorization flow separately. Check out https://aaronparecki.com/2025
47.
▲
by
maxwellg
1y ago
Check out https://github.com/metoro-io/mcp-golang - looks like they support strongly typed tool arguments.
48.
▲
by
maxwellg
1y ago
It looks like there are a few Golang implementations of MCP. The one used in the article doesn't use tags but mcp-golang does. Tags are great! I love tags. - https://github.com/metoro-io/mcp-golang
49.
▲
by
maxwellg
1y ago
Sometimes Go can get under my skin. The MCP SDK makes you jump through all these hoops to configure tools according to a JSON schema, but when it comes to handling the actual request you need to deal with parsing everything again out of a
50.
▲
by
maxwellg
1y ago
MCP uses a date based system for versioning. The most recent specification is 2025-03-26 - https://modelcontextprotocol.io/specification/2025-03-26
51.
▲
Enterprise-Ready MCP
(aaronparecki.com)
1 points
by
maxwellg
1y ago
|
0 comments
52.
▲
by
maxwellg
1y ago
Cool tech. Don’t put a password in something that can be read by anyone with a scanner though.
53.
▲
by
maxwellg
1y ago
Not a founder but our support org is a huge fan of Plain (plain.com) which has some AI features but is mostly a great way to manage both Slack and Email support in one place.
54.
▲
by
maxwellg
1y ago
Being able to make quick changes across a ton of repos sounds awesome. I help maintain a ton of example apps, and doing things like updating a README to conform to a new format, or changing a link, gets pretty tedious when there are 20 diff
55.
▲
by
maxwellg
1y ago
ChatGPT 4o's voice mode has been mindblowing for me for learning basic Mandarin. I'm sure I will hit the limits of the model sooner or later, but it has been so much fun bouncing around my apartment and asking what various objects
56.
▲
by
maxwellg
1y ago
I can't wait for first-party remote MCP servers to become more common. Right now we're taking a strange detour of everyone trying to proxy everyone else's APIs and do manual API Key juggling because platforms aren't runn
57.
▲
by
maxwellg
1y ago
One-dimensionality isn't the issue - the issue is that most drip coffee makers and most cheap to-go coffee is terribly, terribly burnt. The coffee would taste so much better if it was brewed fresh at a lower temperature, but instead yo
58.
▲
by
maxwellg
1y ago
During Covid I spent a lot of time on my home coffee setup - I've since dialed it back but I've kept the pourover, the grinder, and the Chemex. We found a local business that roasts beans in their garage that we love. The biggest
59.
▲
by
maxwellg
2y ago
Neat! Putting in reference books gives you a nice overview of the book's contents. Fun to think of database transactions as a character with relationships. https://austen.pages.dev/c2276990-1f2a-40e6-bd26-0cabb55d713...
60.
▲
by
maxwellg
2y ago
I wasn't around for WSDL so please correct me if I am wrong - but the main weakness of WSDL was that no applications were able to take advantage of dynamic service and method discovery? A service could broadcast a WSDL but something ne
More ›