<div dir="ltr"><br><br><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><br><br class="gmail_msg">
<br class="gmail_msg">
My premise is that there is a very narrow happy medium that we can guess<br class="gmail_msg">
at much more precisely now with all our experience trying to enable<br class="gmail_msg">
applications, work with SaaS, work with IdaaS, work with federation,<br class="gmail_msg">
work without federation, etc. etc. The things we added aren't always<br class="gmail_msg">
things we'd add today.<br class="gmail_msg"><br class="gmail_msg"></blockquote><div><br></div><div>Thats the 80/20 of OIDC at this point (as Scott states as well). Its pretty easy to build into your app and at this point most web server platforms support it (mod_auth_oidc for apache, <a href="http://asp.net">asp.net</a> has a couple of dozen implementations, java has several too). </div><div><br></div><div> </div><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
The premise may be flat wrong, but I hope it's possible to design<br class="gmail_msg">
something that can be explained to application developers without asking<br class="gmail_msg">
or forcing them to rely on a distribution of curious pedigree.<br class="gmail_msg"><br class="gmail_msg"></blockquote><div><br></div><div>most developers i work with that are working on "newer" tech are pretty well versed in oidc because it aligns pretty well to the 12-step-app micro services craze. Wether they implement it CORRECTLY or SECURELY is another matter entirely. Session management is really hard and thats usually where webapps fall down. </div></div></div>