Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

"All of which have their own login system"

You do realize that SAML has been around for a long time? If anything what you want is an executive to tell everyone to use SAML rather than a "senior architect".



If you think you can walk up to 250 legacy systems and "just" do anything, you are not an experienced developer.

An executive can certainly issue the mandate but the project to make it happen is going to be a very detailed one.

It's a good project to do. There shouldn't be 250 ways of doing authentication. Authorization is rather difficult to just wave a magic wand and harmonize, but authentication shouldn't be a cookie here, and a JWT token there, and a microservice with its own tokens that also integrate with some vital system over there, and Basic Auth with LDAP creds over there, and so on.

But the project is going to be a lot more than just standing in a room and shouting "HEY EVERYONE USE SAML, ok, cool, project is now spec'd, timelined, prioritized, and staffed problem solved".




Consider applying for YC's Fall 2025 batch! Applications are open till Aug 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: