Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Just also curious, how difficult/complex would be passkey/password/access recovery with what apppears to be so many layers of auth?


No more complicated than usual, as there's separation of concerns. You'd have your IdP, which provides authentication and account management. The IdP then integrates with an application or service using some authentication protocol (OIDC, SAML, LDAP, etc), so downstream only relies on the protocol.

It could get messy if you had some identity-aware proxy in front of your IdP.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: