How do you propose your average enterprise should manage auth for these legacy systems without using SCIM?
However, I’m curious to learn why you think SCIM is a “bad” protocol, can you explain why you don’t like it?
This has lead to things like popular SAML parsers that do not even attempt to validate the signature. For examples of how this has gone badly wrong, see https://workos.com/blog/fun-with-saml-sso-vulnerabilities-an... .
A slightly longer explanation is that SAML is based on a garbage cryptographic signature standard called “XML-DSig” which, among other issues, allows for partial signatures and stores the signature inside the XML element that it signed.
Honestly, SAML is something of an info hazard. I don’t recommend learning more about it. But if you really want to, this blog post goes into more detail: https://dev.to/workos/fun-with-saml-sso-vulnerabilities-and-...
OpenID was meant to be the successor but popularity wise SAML is still the champion with enterprises.
SCIM doesn't really have a successor afaik. Azure AD I think doesn't do password sync, I am not sure who twisted Okta's hands to get this implemented.
You have a signing authority and it liaisons access. Though it does go in the wrong direction a little bit with SAML
The people who like easy solutions are the Fortune 500.
if someone tells me to sell them shit for 1m ARR i'm going to get squattin and shittin
seems kinda like the responsibility of the person building the application and managing your users' data to do your due diligence on where the keys to the kingdom go
but... on second thought it's crazy that okta even provides this lmao. It's different when you're a SaaS provider with a position of being secure compared to being an indie merc contractor. Hell, if I was an indie merc, I'd straight up just not do it out of principle.