‹ BackHN Continuity

Thread

SAML: A fractal of bad design

353 points · 190 comments · aray07

  1. cameronh90 · · focus · HN ↗
    SAML sucks, but it still has a bunch of features for its specific narrow enterprise SSO use-case that OIDC lacks - most notably IdP-initiated flow. OIDC is a constellation of specs with inconsistent support across products, whereas the commonly-implemented subset of SAML is more-or-less stable in its mediocrity.

    OIDC will eventually displace SAML, but if you're selling to enterprises you should really support both. Both will pale compared to the amount of time you spend dealing with SCIM inconsistencies between IdPs anyway.

    1. blablabla123 · · focus · HN ↗
      > Both will pale compared to the amount of time you spend dealing with SCIM inconsistencies between IdPs anyway.

      I think that's the real problem. Just tying up things with custom, system dependent configurations would probably be more predictable. Most people are probably happy to get the happy path running.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.