Need help?
<- Back

Comments (83)

  • jiggawatts
    I love how the OIDC standard is littered with “authentication identity token code id cookie identifier” and many subtle variations of homonyms in slightly different combinations and orders.I’m sure someone thought it all made perfect sense.Probably someone who never confuses “empathy” and “sympathy” while also carefully distinguishing between “should” and “ought”.
  • nekusar
    Are you fixing it at the IETF and RFC level, or is this just another way to say "BUY OUR SHIT AND IT TOTALLLY SOLVES EVERYTHING!!!!11"
  • andrewshadura
    Unclosable cookie banner. Top notch website engineering.
  • black_knight
    > can this subject perform this action on this object?IMHO, the most elegant method to answer this question is capability based access control. If the subject can utter the action, then it can perform it. And then delegation is the transfer of nouns and verbs to perform the utterances.
  • tuberreact
    turns out naming is important
  • bijowo1676
    excellent article, very thorough and nuanced explanation.
  • usernametaken29
    https://xkcd.com/927Nice work and all regardless
  • zbentley
    “It’s worth being honest about…” yeah, no.
  • kalayciburak
    [dead]
  • rimworld
    [dead]
  • Quarrelsome
    Nice!I'd like to fix the prior abstract. Auth and auth upsets me greatly cos we have:Authentication & Authorizationand we call both/either auth. Hence please help me make this a thing:AuthENTIcation & AuthORIzation : ENTI & ORIENTI- can you enter, ORI (or ORIZ) what can you do?
  • erlich
    What is missing is a graph of all the data and its relationships. Then its just a matter of grouping things together appropriately for humans to understand.It's funny how a graph underlies absolutely everything but no one seems to use them.