HNHacker News
TopNewBestAskShowJobs

hsluoyz

77 karma · joined May 1, 2017

submissionscomments
hsluoyz··on Permission Systems for Enterprise That Scale
Worth mentioning Casbin as well (https://github.com/casbin/casbin) - it's been around for a while and takes a slightly different approach. Instead of being purely Zanzibar-inspired, it uses a PERM (Policy, Effect, Request, Matchers) metamodel that lets you implement RBAC, ABAC, or ReBAC depending on what fits your use case.
hsluoyz··on Auth0 OSS alternative Ory Kratos now with passwordless and SMS support
Casdoor has SMS support long ago: https://casdoor.org/docs/category/sms

Casdoor is much more way powerful than Kratos: https://casdoor.org/

hsluoyz··on Keycloak open redirect: wildcard redirect URIs can be exploited to steal tokens
I'm using Casdoor: https://github.com/casbin/casdoor and glad to see it only has ~77,000 LOC according to the shared link.

Keycloak was good but has too much legacy for 10+ years. Casdoor is pretty new and has become a good replacement for Keycloak for me with more functionalities.

hsluoyz··on Choose your own IP
Casdoor seems to be a good fit as a free solution of SSO: https://casdoor.org/
hsluoyz··on Ask HN: How do you implement authorization in Django?
The Casbin team has built a SaaS called Casdoor to provide Casbin + Django authorizations service: https://www.casdoor.com/
hsluoyz··on Casdoor: Open-source IAM and SaaS management solution
Casdoor is a promising open-source IAM solution: https://casdoor.org/ , written in Go and React. All features like OIDC, OAuth 2.0, SAML, CAS, LDAP, WebAuthn and 2FA are all supported. SaaS management is also supported like pricing, subscription etc.

Source code: https://github.com/casdoor/casdoor

Compared to Keycloak, Casdoor has:

1. Support high-concurrency and use less memory (Go v.s. Java)

2. More modern SPA-style web UI (with React and Ant Design), more CDN friendly

3. full-fledged RESTful API

4. Support a lot of provider types: OAuth, SMS, Email, CAPTCHA

5. More powerful authorization (powered by Casbin), Casbin is a popular authorization solution with a lot of integrations for DBs and applications: https://casbin.org/

SaaS hosting is also provided at: https://casdoor.com/ for anyone who don't want to self-host

hsluoyz··on Keycloak – Open-source identity and access management interview
It's worth a try. Their Casbin is more popular among Go devs. Casdoor is their fairly new project but looks promising
hsluoyz··on Keycloak – Open-source identity and access management interview
Why not use Casdoor? https://casdoor.org

From their system info page: https://door.casdoor.com/sysinfo, it only consumes about 10MB memory and with no less features (more features actually) than Keycloak

hsluoyz··on Keycloak – Open-source identity and access management interview
The fact is a "true" fact, I'm not saying something which is wrong. This is all I care about. I don't need to know why. I'm not an expert on programming languages or look into compiler source code either. If you think the "fact" is not true, plz just give your opinions and evidences.
hsluoyz··on Keycloak – Open-source identity and access management interview
SSO doesn't need SEO. So SPA is OK. The good point is RESTful API is fully exposed without any extra dev work.
hsluoyz··on Keycloak – Open-source identity and access management interview
I's a fact that I also don't know why, maybe not mainly because of GC. Java's high concurrency is not impossible but just requires more efforts to tune the performance
hsluoyz··on Keycloak – Open-source identity and access management interview
Casdoor is another promising open-source IAM solution: https://casdoor.org/ , written in Go and React. All features like OIDC, OAuth 2.0, SAML, CAS, LDAP, WebAuthn and 2FA are all supported.

Compared to Keycloak, Casdoor has:

1. Support high-concurrency and use less memory (Go v.s. Java) 2. More modern SPA-style web UI (with React and Ant Design), more CDN friendly 3. full-fledged RESTful API 4. Support a lot of provider types: OAuth, SMS, Email, CAPTCHA 5. More powerful authorization (powered by Casbin), Casbin is a popular authorization solution with a lot of integrations for DBs and applications: https://casbin.org/

SaaS hosting is also provided at: https://casdoor.com/ for anyone who don't want to self-host

hsluoyz··on Supertokens: Open-Source Alternative to Auth0 / Firebase Auth / AWS Cognito
Another open-source IAM solution called Casdoor looks better than supertokens, it's fully open-source https://github.com/casdoor/casdoor
hsluoyz··on Ask HN: How to implement ABAC authorization for enterprise applications?
I'm Casbin author. XACML is nearly 20 years old and it was a very classic ABAC implementation in the world. I used, learnt and studied it through my master and Ph.D career in the last ten years. That's part of the reason why I created Casbin 3 years ago during my Ph.D. I hope Casbin is some kind of improvement compared to XACML. XACML has been stable these years but Casbin is yound and still growing, so we can fix things that are not that good compared to XACML. Authzforce is under GPL-3, which needs to handle carefully for commercial use. Casbin is Apache 2.0. If you want to follow more famous standard, choose XACML. Otherwise choose Casbin.