However, all server-side attack scenarios listed there are not possible with Hydra. Some of them also boil down to misusing OAuth2 for authentication, which is why we have OpenID Connect.
107 karma · joined October 11, 2016
However, all server-side attack scenarios listed there are not possible with Hydra. Some of them also boil down to misusing OAuth2 for authentication, which is why we have OpenID Connect.
I think removing 3rd party dependencies is always a good idea - it keeps things lean and removes ops overhead.
Also what's your reasoning for relying on 4 (etcd, consul, postgres, nats) external dependencies?
Portier looks indeed very nice, maybe I'll set up a tutorial how to get those two working together to get full Authentication (portier) + Authorization (Hydra) with using only open source technology.
That's why I chose to make it explicit, and thus more likely to be caught in review if done.
If you have any questions, feel free to ask ahead.