Show HN: A microservice that makes adding authentication to your app easy
github.com
github.com
https://oauth.net/articles/authentication/
DO NOT USE THIS in its current state. Stop upvoting this.
Otherwise, an attacker could obtain the target's OAuth token by getting the target to provide the token to a malicious application. The attacker can then easily authenticate through your library.
Given that OAuth is all about delegated authorization, meaning entity that uses the access token may not be the user but some third-party service using the token on behalf of the user, using it as proof-of-identity makes no sense.
This point becomes clearer with limited permissions. If access token is proof-of-identity, why limit what the user can do when you know it's the user?
It's essential to follow best practices, and for developers to understand enough of the interaction to be confident in an implementation.
A few points to look out for after scanning the source for the project:
* if your goal is authentication (helping a user sign in to an app using an external identity) you should be sure to use an OpenID Connect flow (requesting a scope like "openid"), and be sure to convey the id_token back to the app so its signature can be verified.
* you should be sure to create a non-guessable "state" parameter when generating an OAuth authorization request, and to verify this parameter upon completion of the OAuth core flow.
* your design needs to prevent a session fixation attack where a malicious user injects her own token into the callback url (tricking a user into signing into an app using the attacker's account, and potentially submitting data that the attacker can then access the)
* it's best to avoid inserting an access token into a url (where it becomes part of a user's history, gets cached by proxies, etc) -- the OAuth code flow you're using avoids this, but then you turn around and inject the token into your own redirect
So does this mean I need to have Docker and all of the other things mentioned to use this?
Suggestion: Don't couple your product with dev-ops stuff. Try to keep things separate :)
"Ships as a Docker image" might, for a lot of projects, just be a roundabout version of "it's a .zip file; unpack it into /opt"—but I think it's justified if your project is essentially a bunch of distro packages with a layer of policy-glue making them interoperate in a special way. Like OpenStack DevStack, or a NAS server appliance, or an "all-in-one" [L]AMP stack.
You should learn more about docker and dev-ops, because with microservices the focus is increasingly towards having developers support their services end-to-end, which means the devs are responsible for deploying/supporting the services they wrote in production.
Well its one more things to install for starters. Do I need a specific version of docker to run with this? To me it's just an extra layer of complexity.