Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Still waiting for "BFF" https://datatracker.ietf.org/doc/html/draft-bertocci-oauth2-... to gain popularity, the setup seems solid tho slightly more complex compared to these other methods.


BFF is not great for long term security, notably token binding. It's hard enough to bind an artifact to the browser session from the IDP - having each app implement binding passthrough from browser to app to IDP is even worse.


Doesn't this also mean you have to actually have a back end for your site? Can't just host an spa on static web hosting on a cdn.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: