Simplify Login with Application Load Balancer Built-In Authentication
aws.amazon.com
aws.amazon.com
Amazon's solution seems to integrate with a few other identity providers and gives the developers the tools to do authorization after authentication is done. It seems to position this more like a B2B2C. Although it feels like it already subsumes Google's IAP by doing so.
This is my understanding by reading the article on Amazon, I haven't actually used it.
I absolutely agree with the sentiment, so don't get me wrong, but have any cloud provider ever did so? And most importantly, given that such change would impact user confidence, would it really be worth on the long term?
Of course there are several other reasons to avoid vendor lock-in, but as far as "major bad faith pricing change" goes, I believe it's unlikely.
I have an addon that puts CloudFront in front of you Heroku app with one click:
https://elements.heroku.com/addons/edge
I have been thinking about adding auth via Lambda@Edge...
Now I have a nice implementation to copy...
The default connection to your web server should be HTTPS, not HTTP. HSTS is an option to set this up properly.
When the domain is registered to use HSTS their browser will use a TLS connection the first time they ever connect to your website.
> You want those redirected to a HSTS enabled HTTPS connection immediately
Websites that depend on advertising probably do as they often want to support very old browsers. Otherwise there's no real need for a redirect/connection upgrade IMO.
If you don't want to add your domain to the preload list, you will have to (automatically) redirect/upgrade users to HTTPS, or bounce them.
[0] - https://hstspreload.org/
which has the following requirements: 1. Serve a valid certificate. 2. Redirect from HTTP to HTTPS on the same host, if you are listening on port 80.
oops.
> if you are listening on port 80
You don’t have to accept trafic on the http port for HSTS preloading. But iff you do you must redirect it.
This rule makes sense; at least you should never serve content over http.
For things like that, that are very easily solvable other way I don't expect Amazon to work on them anytime soon, if ever.
Also if you use API GW/CloudFront they would do that for you too.
It would make sense to do it in the load balancer, you want to do the redirect as soon as possible. So if you want to do it the correct way you get the option of paying for both ALB and CF.
https://github.com/nzoschke/gofaas/blob/master/docs/security...
In dev I run the same exact code and copy the JWT cookie from my production site.
Both dev and prod have the same secret to validate the cookie.
Quite a number of institutions in my vertical have focused on CAS as opposed to other protocols, hence the ask.
Some benefits:
* Quicker to MVP
* Don't have to rewrite AuthX for each platform (web, iOS, Android, etc)
* Less worrying about the various permutations of 2-factor across all the applicable auth types (username, email, oauth, LDAP)
* Not having to figure out how to federate identity
* Not wanting the burden of GDPR/Privacy compliance in-app
etc.
> Click here to see what info was shared with this website after you authenticated.
This seems fairly easy by comparison.
Try AWS Amplify (https://aws.github.io/aws-amplify/media/authentication_guide) to set up Cognito for your site. Let us know if it still didn’t work - we’d love to help.
Generally speaking you have 30 days to remove personal data (But there is a bit more to it than that).
A good overview is from the UK ICO: https://ico.org.uk/for-organisations/guide-to-the-general-da...