zlacker

[return to "Cloudlflare builds OAuth with Claude and publishes all the prompts"]
1. Etienn+YA[view] [source] 2025-06-02 18:05:31
>>gregor+(OP)
> This is a TypeScript library that implements the provider side of the OAuth 2.1 protocol with PKCE support.

What is the "provider" side? OAuth 2.1 has no definition of a "provider". Is this for Clients? Resource Servers? Authorization Server?

Quickly skimming the rest of the README it seems this is for creating a mix of a Client and a Resource Server, but I could be mistaken.

> To emphasize, this is not "vibe coded". Every line was thoroughly reviewed and cross-referenced with relevant RFCs, by security experts with previous experience with those RFCs

Experience with the RFCs but have not been able to correctly name it.

◧◩
2. DaiPlu+XB[view] [source] 2025-06-02 18:13:59
>>Etienn+YA
> OAuth 2.1 has no definition of a "provider"

Strictly speaking, yes. But speaking of IDPs more broadly, it’s perfectly acceptable to refer to the authorisation-server as an auth-provider, especially in OIDC (which is OAuth, with extensions) where it’s explicitly called “OpenID provider” - so it’s natural for anyone well-versed in both to cross terminology like that.

[go to top]