‹ BackHN Continuity

Thread

SAML: A fractal of bad design

353 points · 190 comments · aray07

  1. ratiolat · · focus · HN ↗
    OIDC is based on Oauth2. The auth part of Oauth stands for authorization, not authentication which brings me to the problem I have with OIDC - namely OIDC is about granting external party access to your data. You can mitigate this a bit via using something like Okta, which just does not have this data, but lets say you don't have Okta and all you have is Google Workspace.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.