Live data from Hacker News

Cloudlflare builds OAuth with Claude and publishes all the prompts

github.com

501–510 of 552 posts

Re: Cloudlflare builds OAuth with Claude and publishes all the prompts

#501
post #490

Earlier quoted context omitted.

> An expert should be able to write that on the scale of an hour. An expert in oauth, perhaps. Not your typical expert dev who doesn't specialize in auth but rather in whatever he's using the auth for. Navigating those sorts of standards is extremely time consuming.

Maybe, but also: Cloudflare is one of like fifteen organizations on the planet writing code like this. The vast majority of The Rest Of Us will just consume code like this, which companies like Cloudflare, Auth0, etc write. That tends to be the nature of highly-specialized highly-domain-specific code. Cloudflare employs those mythical Oauth experts you talk about.

That's me. I'm the expert.

On my very most productive days of my entire career I've managed to produce ~1000 lines of code. This library is ~5000 (including comments, tests, and documentation, which you omitted for some reason). I managed to prompt it out of the AI over the course of about five days. But they were five days when I also had a lot of other things going on -- meetings, chats, code reviews, etc. Not my most productive.

So I estimate it would have taken me 2x-5x longer to write this library by hand.

Re: Cloudlflare builds OAuth with Claude and publishes all the prompts

#502

Fascinating It's like cooking with a toddler The end result has a lower quality than your own potential, it takes more time to be producted, and it is harder too because you always need to supervise and correct what's done

> it takes more time to be producted, and it is harder too because you always need to supervise and correct what's done This is hogwash, the lead dev in charge of this has commented elsewhere that he's saved inordinate amounts of time. He mentioned that he gets about a day a week to code and produced this in under a month, which under those circumstances would've been impossible without LLM assistance.

It took two months for a lead dev and a bunch of "Cloudflare engineers" (to "thoroughly review .. with careful attention paid to security and compliance with standards") to write ~1300 lines of typescript code for a feature they (he ?) masters

If that sounds like "save inordinate amounts of time", well, that's your opinion

Re: Cloudlflare builds OAuth with Claude and publishes all the prompts

#503
post #419

Earlier quoted context omitted.

I tend to disagree, but I don't know what my disagreement means for the future of being able to use AI when writing software. This workers-oauth-provider project is 1200 lines of code. An expert should be able to write that on the scale of an hour. The main value I've gotten out of AI writing software comes from the two extremes; not from the middle-ground you present. Vibe coding can be great and seriously productiv…

> This workers-oauth-provider project is 1200 lines of code. An expert should be able to write that on the scale of an hour. Are you being serious here? Let's do the math. 1200 lines in a hour would be one line every three seconds, with no breaks. And your figure of 1200 lines is apparently omitting whitespace and comments. The actual code is 2626 lines. Let's say we ignore blank lines, then it's 2251 lines. So one l…

"On the scale of an hour" means "within an order of magnitude of one hour", or either "10 minutes to 10 hours" or "0.1 hours to 10 hours" depending on your interpretation, either is fine.

Re: Cloudlflare builds OAuth with Claude and publishes all the prompts

#504

Earlier quoted context omitted.

> Though, people who don't know the codebase as well as I do have reported it helped them a lot. My problem I guess is that maybe this is just Dunning-Kruger esq. When you don't know what you don't know you get the impression it's smart. When you do, you think it's rubbish. Like when you see a media report on a subject you know about and you see it's inaccurate but then somehow still trust the media on a subject you'…

> My problem I guess is that maybe this is just Dunning-Kruger esq. When you don't know what you don't know you get the impression it's smart. When you do, you think it's rubbish. I see your point. Indeed there are two completely different points of view regarding the output of LLMs: * Hey, I managed to vibecode my way into a fully working web service with a React SPA after a couple of prompts, and a full automated t…

> The truth of the matter is that the vast majority of software engineers write crap code, as the definition of "crap code" is "something I would have done differently".

This is certainly a part of it, but I do wonder that even if an LLM “learned” the conventions and preferences of an engineer and spit out “perfectly styled” code, would it be treated as such? I’d wager (a small amount) that it wouldn’t, because part of enjoying the code - for me - is _knowing_ the code. “I wrote it this way because I tried X, then Y, then saw I could do Z, and now I’m familiar with the code in a way that’s more intimate.” Unfamiliar code rarely looks like _really good_, in my opinion.

Re: Cloudlflare builds OAuth with Claude and publishes all the prompts

#505

I very much appreciate the fact that the OP posted not just the code developed by AI but also posted the prompts. I have tried to develop some code (typically non-web-based code) with LLMs but never seem to get very far before the hallucinations kick in and drive me mad. Given how many other people claim to have success, I figure maybe I'm just not writing the prompts correctly. Getting a chance to see the prompts sh…

This is something that I have noticed as well. As soon as you venture into somewhat obscure fields, the output quality of LLMs drastically drops in my experience. Side note, reverse engineering SAP ABAP sounds torturous.

[dead]

Re: Cloudlflare builds OAuth with Claude and publishes all the prompts

#506

Earlier quoted context omitted.

I really don't agree with the idea that expert time would just be spent typing, and I'd be really surprised if that's the common sentiment around here. An expert reasons, plans ahead, thinks and reasons a little bit more before even thinking about writing code. If you are measuring productivity by lines of code per hour then you don't understand what being a dev is.

> I really don't agree with the idea that expert time would just be spent typing, and I'd be really surprised if that's the common sentiment around here. They didn't suggest that at all, they merely suggested that the component of the expert's work that would otherwise be spent typing can be saved, while the rest of their utility comes from intense scrutiny, problem solving, decision making about what to build and wh…

Time spent typing is statistically 0% of overall time spent in developing/implementing/shipping a feature or product or whatever. There's literally no reason to try to optimize that irrelevant detail.

Re: Cloudlflare builds OAuth with Claude and publishes all the prompts

#507

The commits are revealing. Look at this one: > Ask Claude to remove the "backup" encryption key. Clearly it is still important to security-review Claude's code! > prompt: I noticed you are storing a "backup" of the encryption key as `encryptionKeyJwk`. Doesn't this backup defeat the end-to-end encryption, because the key is available in the grant record without needing any token to unwrap it? I don’t think a non-expe…

this seems like a true but pointless observation? if you're producing security-sensitive code then experts need to be involved, whether that's me unwisely getting a junior to do something, or receiving a PR from my cat, or using an LLM. removing expert humans from the loop is the deeply stupid thing the Tech Elite Who Want To Crush Their Own Workforces / former-NFT fanboys keep pushing, just letting an LLM generate c…

> …removing expert humans from the loop is the deeply stupid thing the Tech Elite Who Want To Crush Their Own Workforce…

this is completely expected behavior by them. departments with well paid experts will be one of the first they’ll want to cut. in every field. experts cost money.

we’re a long, long, long way off from a bot that can go into random houses and fix under the sink plumbing, or diagnose and then fix an electrical socket. however, those who do most of their work on a computer, they’re pretty close to a point where they can cut these departments.

in every industry in every field, those will be jobs cut first. move fast and break things.

Re: Cloudlflare builds OAuth with Claude and publishes all the prompts

#508

The commits are revealing. Look at this one: > Ask Claude to remove the "backup" encryption key. Clearly it is still important to security-review Claude's code! > prompt: I noticed you are storing a "backup" of the encryption key as `encryptionKeyJwk`. Doesn't this backup defeat the end-to-end encryption, because the key is available in the grant record without needing any token to unwrap it? I don’t think a non-expe…

That is how LLM:s should be used today. An expert prompts it and checks the code. Still saves a lot of time vs typing everything from scratch. Just the other day I was working on a prototype and let claude write code for a auth flow. Everything was good until the last step where it was just sending the user id as a string with the valid token. So if you got a valid token you could just pass in any user id and become…

Sure! But over half the fun of coding is writing and learning.

Re: Cloudlflare builds OAuth with Claude and publishes all the prompts

#509

Earlier quoted context omitted.

A prompt can be as little as a sentence to write hundreds of lines of code.

Hundreds of lines that you have to carefully read and understand.

Are you not doing that already?

I go line-by-line through the code that I wrote (in my git client) before I stage+commit it.

Re: Cloudlflare builds OAuth with Claude and publishes all the prompts

#510
Is this not... embarrassing? to the engineers who submit these commits?

It seems that way to me...

Certainly if I were on a hiring panel for anyone who had this kind of stuff in their Google search results, it would be a hard-no from me -- but what do i know?

Post reply on HN