Not surprised, but still disappointed.
Not surprised, but still disappointed.
OAuth is about getting access to something, and usually part of that is proving to some authorization server that you are you (ie what OpenID is about), no?
Do you mean you'd like OAuth to tackle the "you are you" part as well?
authZ = authoriZation (access / "what are you allowed to do")
OAuth => think authZ
OIDC => think authN
And auth0 ("auth Zero, not letter o") is a company / service that offers both authN and authZ.
As a website developer I would definitely appreciate something like OpenID but actually usable/popular. Having to implement a ton of "log in with"s sucks, as does implementing email based login.
This is kind of auth0's--but also most security token service things--raison d'etre: your app trusts just one authority and supports just one protocol, shunting any unauthenticated users to it, letting it handle the transaction with trusted identity providers.
How could the specification support letting the end-user pick their authorization provider? Should the RC suggest the AS instead of the RS doing so?