Live data from Hacker News

Easy to use OpenID Connect client and server library written for Go

github.com

41–47 of 47 posts

Re: Easy to use OpenID Connect client and server library written for Go

#41
post #4

Having built and worked with a variety of oidc implementations. It is an incredibly misused technology, while it initially can be easy to integrate into your app. It increases the complexity of the app to a surprising degree. Now suddenly your little webapp have to handle how various devices handle redirects to external sites, receives callbacks. And all the weird ways oidc implementations uses cookies, handles retur…

Not looking for your source code, what shape did your solution take? Does it single sign on? Single sign off? How do you convey permissions and groups? Is your app the source of truth, or do you read users and groups out of another IdP?

Re: Easy to use OpenID Connect client and server library written for Go

#42

I would like to become more knowledgeable about authentication and identification tech stacks (LDAP, OIDC, Oauth, CAS, etc.) and have hands-on experience. I already dabbled a bit with some LDAP, I have professional experience in administering linux boxes and intranet infrastructure. Where should I begin if I want to set up a simple homelab with maybe a raspberry and some NUC ?

Take a historical journey by setting up an LDAP server like OpenLDAP or Samba, add Keycloak on it (or just use Keycloak for LDAP too), then integrate it to AWS using SAML and Google using OIDC.

Re: Easy to use OpenID Connect client and server library written for Go

#43
post #9
post #5

Earlier quoted context omitted.

how various devices handle redirects to external sites Isn't a simple redirect in the same window enough? Redirect to OIDC provider -> login -> redirect back APP -> get OIDC state from URI params?

At the most basic yes, but the protocol doesn't describe what the login part is and how that works. Often it implements session using cookies, which given the state you were in previously. Maybe you wanted to embed the login page on your own site (iframe or webview), now the cookies are flagged as third party cookies and blocked in a variety of context. Especially in an app context it becomes a minefield of half bake…

Isn't the "state" parameter often used for including the return url? Similar to RelayState in SAML2?

Re: Easy to use OpenID Connect client and server library written for Go

#44
I can't recommend enough Zitadel and its OIDC library. Code is very well-writen and informative.

Highly encourage everyone jump into source code and explore how IntrospectionResponse struct work with all related code around

https://github.com/zitadel/oidc/blob/main/pkg/oidc/introspec...

// IntrospectionResponse implements RFC 7662, section 2.2 and

// OpenID Connect Core 1.0, section 5.1 (UserInfo).

// https://www.rfc-editor.org/rfc/rfc7662.html#section-2.2.

// https://openid.net/specs/openid-connect-core-1_0.html#Standa....

type IntrospectionResponse struct { Active Scope ClientID TokenType ... exp iat nbf sub Audience ... aud ... JWTID ... Claims map[string]any }

If you want to explore the difference between identity providers, click through

https://github.com/nextauthjs/next-auth/tree/main/packages/c...

Azure is the most insane ... and it's a lot of fun to compare them all against each other.

Next go though PKCE (Proof Key for Code Exchange) and look how code_challenge, code_verifier works or at least see interfaces .

Ory Fosite is a great alternative too https://github.com/ory/fosite

Support PKCE #59835 in x/oauth2 https://github.com/golang/go/issues/59835

Scott Brady's content is great for undetstanding the topic

SPA Identity and Access Control with OpenID Connect https://www.youtube.com/watch?v=rP3St0GU_Bk OAuth is Not Authentication https://www.scottbrady91.com/oauth/oauth-is-not-authenticati...

SPA is a landmine ..

OAuth 2 0 and OpenID Connect for Single Page Applications Philippe De Ryck https://www.youtube.com/watch?v=XoBtUn4XczU

The deeper you go into the topic the more you will discover. It's an ultimate "rabbit hole" - web, native, SPA flows, PKCE, JWT, session storage, custome middleware for your favorite flavor of backend framework, etc

Re: Easy to use OpenID Connect client and server library written for Go

#45

Just two days ago I wrote a comprehensive tutorial on how openid connect works using simple http requests to understand the flow: https://spapas.github.io/2023/11/29/openid-connect-tutorial/ It has been written with keycloak as the auth server but should work for any proper openid connect implementation since I used the specification as a guide.

This is excellent, thank you!!

Re: Easy to use OpenID Connect client and server library written for Go

#46

I went with using Keycloak for a platform I'm developing right now and it feels like a very overcomplicated enterprise piece of software - it still does work and has the features that I need (notably: an SSO login portal, user registration, password resets and social login), but definitely needed a certain amount of time to configure correctly and had odd bugs, like me needing the following in my reverse proxy config…

> one user might be related to multiple organizations, having different permissions in the context of each

Multitenancy is hard, messy and error-prone. Do you really need it, or maybe you could be happy with user-per-tenant scheme?

Re: Easy to use OpenID Connect client and server library written for Go

#47
post #38

Earlier quoted context omitted.

Have you considered/tried Ory Kratos + Hydra [0]? I've never used either Ory or Keycloak, but out of these 2, Keycloak feels more opinionated and harder to set up, though it does have more features. [0] https://www.ory.sh/open-source/

Hydra and Kratos do not come with any frontend components, it's essentially just an API you have to write a a much more opinionated client for.

This is a unique feature of Kratos/Hydra, you can use your own frontend components. With many other implementations this is not possible. What do you mean by "much more opinionated client", there is a set of standard flows that your app has to handle and thats it for most cases.

If you want out of the box components they also have a paid version for that (and code examples in OSS)

Post reply on HN