HNHacker News
TopNewBestAskShowJobs

malachygr

215 karma · joined August 28, 2018

submissionscomments
malachygr··on Approaching Access Control on the Web (Part I)
Right, in German we say "ultimativ" so that's the reason :)
malachygr··on Approaching Access Control on the Web (Part I)
> * There are a handful of typos scattered through the text, about 5-10 errors

Should be fixed now!

> Can you give an example on this?

An anonymous user is not authenticated but may still access some data.

> * Server-Side Distributed Applications, I don't have a solid conviction but I can't really see how multiple systems with multiple parallell accounts is a common, viable or even realistic situation...

This is actually not that unusual. Mostly happens when a company buys or uses a third-party CRM / SaaS or whatever!

malachygr··on Approaching Access Control on the Web (Part I)
Yes, but we're also moving to open collective for this. Patreon is more for individuals while open collective is for open source collectives.
malachygr··on Approaching Access Control on the Web (Part I)
Hi, mostly consulting, sponsorship and paid additions to the open source ecosystem. In the future we'll offer managed cloud services. We're not doing open core though, if that's what you're getting at :)
malachygr··on Approaching Access Control on the Web (Part I)
Never :) No affiliation with Palantir!
malachygr··on Approaching Access Control on the Web (Part I)
Hey! That's a great point. John (our designer) is currently on vacation but he will create some animated SVGs which make this easier to digest!

We were also thinking to have an interactive "decision map" where you start with what type of application you develop (e.g. prototype, distributed app, ...) and step-by-step come closer to a recommendation from us. We might also include some software in the last step to guide you to the right pieces. Would that be something you'd like to see?

malachygr··on Approaching Access Control on the Web (Part I)
Hi there! From experience we know how hard auth* systems can be. There are a million ways to get what you want. We also see the issue that developers usually start with a least-effort approach (username + password) which needs refactoring later on. The intention of these articles is to give you an overview of what exists and help you choose the best approach with as much information as you can get. We hope that this saves you some time. If you haven't heard from us before, I welcome you to check out our open source products which are all related to auth*: https://github.com/ory

We will plug some of these (and other) open source products in the articles, but we really want to teach you something. There is so much SEO-optimized onboarding (for expensive blackbox SaaS) content with little substance on this topic. We really hope this helps you!

One last thing: We hope it's ok that the other parts are not ready yet. Aeneas (author of the guide) is trying to push out one ~ every month! Getting this content right is a lot of work :)

Cheers!