zlacker

[parent] [thread] 2 comments
1. kenton+(OP)[view] [source] 2025-06-02 23:00:50
While implementing the OAuth standard itself is not novel, many of the specific design details in this implementation are. I gave it a rather unusual API spec, an unusual storage schema, and an unusual end-to-end encryption scheme. It was totally able to understand these requests, even reasoning about the motivation behind them, and implement what I wanted. That's what convinced me.

BTW, the vast majority of JS OAuth libraries are implementing the client side of OAuth. Provider-side implementations are relatively rare, as historically it's mostly only big-name services that ever get to the point of being a OAuth providers, and they tend to build it all in-house and not release code.

replies(1): >>blibbl+91
2. blibbl+91[view] [source] 2025-06-02 23:08:39
>>kenton+(OP)
I think you're easily convinced.
replies(1): >>Throwa+Xo
◧◩
3. Throwa+Xo[view] [source] [discussion] 2025-06-03 02:41:35
>>blibbl+91
I think you'll never be impressed.
[go to top]