Ie can I log in to Google with Obligator? Or do I need to set up each client beforehand?
I skimmed the related article but didn't get it entirely, I'll need to read it more thoroughly.
The original vision of OpenID (ie pre-OpenID Connect) was for applications to support any IdP, and you just tell the app what your IdP is when you create your account. You could also imagine browsers filling this in automatically. This didn't pan out in practice, primarily because no one used it[0].
However, it's becoming more realistic to run your own IdP, both by self-hosting and by using services such as Okta.
Tailscale actually let's you bring your own OIDC IdP. It uses WebFinger to prove an IdP has authority over a specific identity (email address). This is even more streamlined than entering your IdP directly. You just give Tailscale your email and they automatically send your to your IdP to authenticate.
But I wouldn't hold your breath for the major email providers to implement WebFinger so users can choose their own IdP. Which is one of many reasons I'm a big advocate of people using their own domain for email, even if the email itself is hosted by someone else (I use and love Fastmail).
[0]: https://meta.stackexchange.com/questions/307647/support-for-...
I was so sad to see it die.
So, I build some app for Wordpress sites and self-hosters want to use my app against their WP site that they also made into an IDP. Then we get the issue of the app needing to be (pre)registered with the IDP, and set client_id and client_secret in its config.
Okay. I get that. But why on earth are we assuming that a self-hoster who can setup her own IDP cannot also create this app registration herself, and add a client_id/secret to a configfile before starting my app?
Excellent question, and it gets into the meat of why I made this in the first place. obligator is the first piece of the puzzle I'm trying to solve to make self-hosting as easy and secure as running an app on your phone. In that world users cannot be expected to pre-register OAuth2 applications. But above and beyond that, registration creates friction that I feel is unnecessary and doesn't add enough additional security (and as mentioned can even reduce security when implemented poorly) for me to want to bother with it myself, so I built a server that doesn't require it.
The above post was also linked from the obligator project's GH readme
Also, near the end of the article. Using a security nightmare such as Wordpress as your identity provider, what could go wrong? It only takes one single rogue plugin.