las2peer icon indicating copy to clipboard operation
las2peer copied to clipboard

[ENH] Support authentication only via OIDC

Open ThoreKr opened this issue 3 years ago • 0 comments

Motivation

Services which do not make use of extended agent features, such as the requirements bazaar, currently employ the anti pattern of shared, reused passwords which are known to any service which got an access token from the same identity provider.

Furthermore sending the access token in a separate header could become another thread to the users privacy as http agent mechanisms to strip the auhorization header when following redirects are ineffective.

Ideally, to decrease integration efforts and to encourage the use of standard libraries, authentication should be possible through a regular oidc flow, without the need for additional tweaks and headers.

ThoreKr avatar May 26 '21 21:05 ThoreKr