Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

ODIC cannot operate with a private-network IdP.

SAML can.

In general, SAML is complicated because (1) auth is complicated (2) XML is complicated (3) canonicalization/signatures are complicated.

Some of those are unforced errors, some are historical facts.



> ODIC cannot operate with a private-network IdP

Why not? The flow can be entirely client side. OpenID discovery and PAR is optional and those would require direct connections


Yes, you could develop a client-side (JavaScript) application to do this.

SAML does not require JavaScript to do that.


Neither does OpenID Connect, it is all form submits or GET redirects.



Consider applying for YC's Winter 2027 batch! Applications are open till November 2.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: