User avatar
flori_ava_star:~cursor_blinking made-with-estrogen verifiedlesbian @star@amazonawaws.com
8h
It is, to me, crazy that OIDC is the best thing we collectively have as an industry, and it just doesn't specify things such as... how to list all active sessions. Honestly, OIDC is very nice, but WOW does it have a *lot* of gaps which force you to do really funky shit to be able to have functionality which sounds very basic on the surface
❤️1
1
0
6
1

User avatar
aura @aura@gts.foxsnuggl.es
8h
@star uhhh, that's super out of scope?
1
0
0
0
User avatar
flori_ava_star:~cursor_blinking made-with-estrogen verifiedlesbian @star@amazonawaws.com
8h
@aura I would argue it is not out of scope. You already have session management. There should just be an RFC extending on this.
2
0
0
0
User avatar
flori_ava_star:~cursor_blinking made-with-estrogen verifiedlesbian @star@amazonawaws.com
8h
@aura What is "in scope" for any protocol is entirely arbitrary
:neocat_sad@horny.jetzt:1
0
0
0
1
User avatar
aura @aura@gts.foxsnuggl.es
8h
@star except you really don't have session management, you have some primitives in an optional spec that can pretty much only signal a logout event
1
0
0
0
User avatar
aura @aura@gts.foxsnuggl.es
8h
@star also imo that spec is incredibly silly, if you want the same properties, issue shorter tokens and refresh once it expires (or use back-channel logout which checks more compliance boxes anyway)
2
0
0
0
User avatar
aura @aura@gts.foxsnuggl.es
8h
@star but also, oidc is a pretty broad protocol, listing sessions kind of implies choice of database tech in some ways whereas the existing spec can be entirely implemented with a key-value store (for super large deployments)

this is a provider i wrote at work and... it doesn't do state at all!
0
0
1
0
User avatar
flori_ava_star:~cursor_blinking made-with-estrogen verifiedlesbian @star@amazonawaws.com
4h
@aura Yes true but to me it's just about having a standard for it, so that I know that stuff I design works with multiple IdPs
0
0
0
0