‹ BackHN Continuity

Thread

SAML: A fractal of bad design

353 points · 190 comments · aray07

  1. paulddraper · · focus · HN ↗
    ODIC cannot operate with a private-network IdP.

    SAML can.

    In general, SAML is complicated because (1) auth is complicated (2) XML is complicated (3) canonicalization/signatures are complicated.

    Some of those are unforced errors, some are historical facts.

    1. sebazzz · · focus · HN ↗
      > ODIC cannot operate with a private-network IdP

      Why not? The flow can be entirely client side. OpenID discovery and PAR is optional and those would require direct connections

      1. paulddraper · · focus · HN ↗
        Yes, you could develop a client-side (JavaScript) application to do this.

        SAML does not require JavaScript to do that.

        1. sebazzz · · focus · HN ↗
          Neither does OpenID Connect, it is all form submits or GET redirects.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.