30 ms·
Okta's NextJS-0auth troubles
- Traubenfuchs 10mo agoIs there any non shite managed oAuth solution with a free tier available? Auth0 really is super easy and comfortable to integrate and I don‘t want to run my own keycloak or whatever.
- trollbridge 10mo agoAuthentik?
- Traubenfuchs 10mo ago> Replace Okta Aren't they cheeky! Thanks, I will try.
- dovys 10mo agoYou're either free OSS that gets flooded with AI slop PRs to overwhelm maintainers or you're a corporate OSS that uses AI slop to frustrate contributors. Are there any positive stories I've not seen?
- cedws 10mo agoThat’s funny. I spotted a similar issue in their Go SDK[1] a few years back. I was pretty appalled to see such a basic mistake from a security company, but then again it is Okta. [1]: https://github.com/okta/okta-sdk-golang/issues/306 https://github.com/okta/okta-sdk-golang/issues/306
- cookiengineer 10mo agoKind of funny that stalebots are the new "won't fix" methodology to ignore security issues with plausible deniability.
- c-hendricks 10mo agoYeah I got a kick out of that. "We might have fixed your issue, if we didn't, open a new one because we took so long acknowledging this one".
- OptionOfT 10mo agoOr 3 years later: can you verify this is still needed. Why on earth did I spend time in creating a reproducible example?
- op00to 10mo agoPeople move on from issues. You apply a workaround, and the fix is no longer needed. Not every issue opened needs a fix. We all have limited resources, and prioritize the most important stuff to fix.
- cookiengineer 10mo agoA stalebot marks it as inactive because you didn't take 2mins of your time to write a thank you, it's been fixed with commit xyz. That's what the critique is about, lack of communication and lack of acknowledgement. Ghosting people when they took the time to file an issue/bug report, with providing a PoC and test case is just rude behavior.
- jonathaneunice 10mo ago> I was pretty appalled to see such a basic mistake from a security company, but then again it is Okta. Oh. Em. Gee. Is this a common take on Okta? The article and comments suggest...maybe? That is frightening considering how many customers depend on Okta and Auth0.
- DetroitThrow 10mo agoSecurity companies that prioritize bugs being sold rather than be reported will eventually blow up. Good luck Okta shareholders.
- acessoproibido 10mo agoUnfortunately security is wayyyy down on the list of priorities for most large companies
- Will-Reppeto 10mo ago[flagged]
- roze_sha 10mo agoIs this ai generated
- transcriptase 10mo agoMore than likely. Look at the users most recent comment with the random “ at the end too.
- hypeatei 10mo agoI think GitHub should allow disabling PRs. I don't believe most big corporations are interested in dealing with fly-by contributions because it might make them look bad or be riddled with quality issues. Also some projects like the Linux kernel are just mirrors and would be better off with that functionality disabled.
- jchw 10mo agoWhile that is true, I feel like it is irrelevant here since it seems like Okta definitely wants (and perhaps needs) the fixes. God only knows why GitHub still forces it on though. Early on it might've been some mechanism to encourage people to accept contributions to push the social coding aspect, but at this point I have no idea who this benefits, it mostly confuses people when a project doesn't accept PRs.
- hypeatei 10mo ago> Okta definitely wants (and perhaps needs) the fixes They definitely don't want them if their process requires signed commits and their solution is 1) open another PR with the authors info then sign it for them, and 2) add AI into the mix because git is too hard I guess? No matter how you slice it, it doesn't seem like there are Okta employees who want to be taking changes from third parties.
- jchw 10mo agoI think that they absolutely still want the free labor. All of those signals just suggest that they're not willing to reciprocate any effort that you put in when you contribute.
- petre 10mo agoSocial on today's Internet = bots and occasionally trolls
- deleted 10mo ago[deleted]
- 10mo ago
- jchw 10mo agoIANAL but unfortunately, I think the fix itself shown here might be too simple to actually clear the bar for copyright eligibility. (And in fairness to copyright law, it is basically the only sane way to fix this.) That means that there's probably not much you can really do, but I will say this looks fucking pathetic, Okta.
- rikafurude21 10mo agoI'm more confused by the fact that the OP freely submits a PR into an open source repo but then wants to use "copyright" because the code he submitted ended up being used under the wrong name, which was then corrected.
- detaro 10mo agoWhy is it confusing to you to expect attribution?
- rikafurude21 10mo agothats not the confusing part, its rather confusing to threaten to sue for copyright because of mistaken attirbution
- cyberpunk 10mo agoHe even asked them to force-push a new history because they got the name wrong! Mistakes happen, I guess this hurts his 'commits in a public repo' cv score.
- abigail95 10mo agoMistaken attribution, or taking something that doesn't belong to you and saying it belongs to someone else is a core function of copyright law and should not be confusing to anyone who has dealt with it before. What is your understanding of what license and rights the author was providing them - understanding this I can figure out where you are confused.
- 10mo ago
- Yasuraka 10mo agoOkta is, if you may excuse my French, straight garbage.
- altairprime 10mo agoAnd too bad for everyone who was using their former competitor Auth0.
- torton 10mo agoI had a fairly fun time using Auth0 a few years back. The ability to run arbitrary code hooks at various points allowed us to do pretty interesting stuff in a managed way without resorting to writing or self-hosting something that was entirely flexible.
- sbmthakur 10mo agoWhy if I may ask?
- Hnrobert42 10mo agoIt's a fair question. I found them way better to implement SSO in my small startup than OneLogin. Using Auth0 in apps, I find their documentation bafflingly difficult to read. It's not like being thrown in the deep end unexpected to swim. It's like being injected at the bottom of the deep end.God help the poor non-native English speakers on my team who have to slog through it.
- Yasuraka 10mo agoSecurity and safety is all over their marketing but I have yet to hear anything about them that doesn't indicate either bumbling incompetence or gross negligence.
- stronglikedan 10mo agoThe fact that they have a "stay signed in" checkbox that doesn't keep me signed in tells me all I need to know about these jokers. I love going through a bloated login process multiple times a day, apparently.
- rcleveng 10mo agoHonestly when I saw Okta in the headline, I had assumed the article was going to say they were breached again. This one is amusing, and as another comment mentioned below, large companies are awful at accepting patches on github. Most use one-way sync tools to push from their internal repositories to github.
- Aldipower 10mo agoWTF is Okta?
- mananaysiempre 10mo agoAn auth integrator, a pretty notable one, mostly (originally?) OAuth I think. Multiple people calling it a trash fire here came as a surprise to me, but I defer to their experience.
- trollbridge 10mo agoOkta was state of the art a decade ago.
- claaams 10mo agoPeople calling it trash and then recommending microsoft was an even bigger shock to the point where I am not convinced that those aren't microsoft AI bots astroturfing this post.
- pluralmonad 10mo agoYeah, wasn't essentially every Azure resource wide open for exploitation until august of this year? https://dirkjanm.io/obtaining-global-admin-in-every-entra-id-tenant-with-actor-tokens/ https://dirkjanm.io/obtaining-global-admin-in-every-entra-id...
- mrweasel 10mo agoBasically an enterprise single sign on solution. We use it to allow staff to sign into pretty much any external service using Gsuite credentials.
- theoldgreybeard 10mo agoYou couldn't pay me a billion dollars to use Okta.
- mrcwinn 10mo agoYou just literally saved me one billion dollars. The offer was incoming!
- pphysch 10mo agoSadly many people will spend a million dollars to use Okta for their 10,000 logins/day (read: <1 tps) instead of running their own Keycloak or Authentik or whatever. OIDC is not scary, and advanced central authorization features (beyond group memberships) are a big ole YAGNI / complexity trap.
- trollbridge 10mo agoThe workload to run Authentik locally is about identical to the workload to set up and configure Okta. (Or you could just fine someone who will host Authentik for you, if deploying a container is too hard for you.)
- p_ing 10mo agoRunning your own local AuthN/AuthZ is more than just 'install it on a box in the closet'. I don't blame anyone for letting one of the giants do this on their behalf -- they have the expertise, though I agree I wouldn't touch Okta.
- pphysch 10mo agoFor your average enterprise it really is that simple. Register some IDPs. Connect a backend. Add some clients over time. Yes, you need someone to wear the IAM admin hat. But once you get it configured and running it requires 0.1 FTE or less (likely identical to whatever your Okta admin would be). Not worth 6+ figures a year and exposure to Okta breach risk.
- 10mo ago
- twodave 10mo agoI LOVE LLMs as a learning tool. I HATE LLMs as a communication tool. I know, there are people with serious handicaps who benefit from LLMs in this area. If only I could talk to those people and not wade through all this other garbage. Especially when the AI is being represented as a person, this to me is dishonest. Not to mention annoying, almost more-so than the number of different apps that think they are important enough to send me push notifications to fill out a survey (don’t even get me started).
- whichquestion 10mo agoLLMs have definitely helped me reduce my social anxiety when writing, especially in a technical work setting. I don’t use it like the respondent in the article though, I would feel really embarassed to not edit an llm’s output to be in my own voice. But I feel it helps provide me with some structure in whatever I’m trying to write when I don’t have the mental energy or wherewithal to provide it myself.
- twodave 10mo agoI agree. I’ve used LLMs to aid in writing out copy and other things, but as a learning tool and not as a way to remove myself from the process. I especially don’t like where businesses are taking this. At least with the old chat bots and such you knew you were in an equivalent of a phone tree. Now it’s hard to tell what’s human and what isn’t, and therefore difficult to know how to interact.
- RagnarD 10mo agoI've been quite happy with FusionAuth so far. Free to run on your own server, easy to understand and set up, easy to program against, reliable.
- wingmanjd 10mo agoWe're another happy FusionAuth customer. We started with self-hosted but just moved to their hosted option this year.
- filearts 10mo agoI think it is distasteful and disrespectful to call out an employee by name in this way, regardless of the merit of the rest of the OP's post.
- iloveplants 10mo agowell, it was distasteful of to them to close op's pr and apply the same patch with improper attribution, and then use ai to respond when they were asked about it
- deleted 10mo ago[deleted]
- atonse 10mo agoI agree with the parent post that it's distasteful. There's no value in naming the employee. Whatever that employee did, if the company needed to figure out who it was, they can from the commit hashes, etc. But there's no value in the public knowing the employee's name. Remember that if someone Googles this person for a newer job, it might show up. This is the sort of stuff that can disproportionately harm that person's ability to get a job in the future, even if they made a small mistake (they even apologized for it and was open about what caused it). So no, it's completely unnecessary and irrelevant to the post.
- Exoristos 10mo ago> This is the sort of stuff that can disproportionately harm that person's ability to get a job in the future. Isn't that beneficial in this case?
- Freak_NL 10mo ago> Remember that if someone Googles this person for a newer job, it might show up. Not to sound too harsh, but this is a person who rudely let AI perform a task badly which should have been handled by just… merging/rebasing the PR after confirming it does what it should do, then couldn't be bothered to reply and instead let the robot handle it, and then refused to fix the mess they made (making the apology void). That's three strikes.
- avree 10mo agoFWIW, the employee reply (who the author is putting on blast) seems like it was written by a human, not an AI. "You're absolutely right!" is the Claude cliche (not a ChatGPT one) - "You are absolutely correct." is not that.
- DrammBA 10mo agoDirectly from the employee (tusharpandey13) in the github PR: > Yeah, i had to manually stop it and delete the ai-generated comment.
- Brian-Watkins 10mo ago[flagged]
- DrammBA 10mo agoI find it funny that this seemingly fictitious person Simen A. W. Olsen my@simen.io will forever be engraved as a co-author of a one-line change in the nextjs-auth0 repo.
- letmetweakit 10mo agohttps://who.is/whois/simen.io https://who.is/whois/simen.io He's not fictitious I think.
- syncsynchalt 10mo agoSimen Olsen is not fictitious, but the "my@" email/username seems to be. Zero hits on DDG, and only this article comes up in Google Search.
- verdverm 10mo agoSearch has become so bad that zero hits is not the indicator it used to be, even DDG is struggling now. It's really evident in situations like this where you are looking for something specific. Seems like they all pushed too hard on the AI and the results are for averaged search queries. Using quotes and -term have become less helpful Conspiratorially, I wonder if this is intentional to drive more traffic to ai. I find myself using Google Deep Search more, which is honestly a better UX if it would stop writing damn reports and just give me a brief with links. Alas it ignores any instructions to change it's output format
- merrvk 10mo agoThat maintainer seems clueless
- fudged71 10mo agoI'm currently building on the Auth0 SaaStarter because it seemed to be the only option in the market for something with all the core features enterprises are looking for. Is there an alternative that doesn't require building from scratch?
- yahoozoo 10mo ago[dead]
- deleted 10mo ago[deleted]
- deleted 10mo ago[deleted]
- deepsun 10mo agoOkta requiring to create a video for a pretty obvious vulnerability shows that Okta does not take security seriously, contrary to what they say at their earnings calls. Sounds like deceiving their investors.
- deleted 10mo ago[deleted]
- burnt-resistor 10mo agoDon't outsource SSO to any IdMaaS. It's too critical. And especially not to Okta.
- YouAreWRONGtoo 10mo ago[dead]
- glemmaPaul 10mo agoAnyone that uses Okta should be accepting the fact that they have outsourced a huge chunk of responsibility of their job onto an enterprise company. These github links are not open source projects, these are public readable software projects. You do not control any of it, you have to deal with internal company politics like "# PRs opened", "# Bugs solved" for the developers' next performance review.
- sintax 10mo agoWhat do you expect? This is the same company suggesting people to turn off DNS Rebind protection to work around their incompetence (https://support.okta.com/help/s/article/dns-rebind-protection?language=en_US https://support.okta.com/help/s/article/dns-rebind-protectio...)
- rckt 10mo agoAI enabled engineers. Dammit, things like this trigger a very strong rejection of actively adopting AI into my workflows. Not the AI tooling itself, but the absolutely irresponsible ways of using it. This is insane.
- donalhunt 10mo agoSeems the perfect opportunity to create a AI-generated "hackers" short with some prepared screenshots. /s
- ovo101 10mo agoWhat’s frustrating here is how predictable these issues are. Next.js isn’t some niche framework, yet Okta’s SDK still struggles with basic OAuth flows like redirect handling, cookie persistence, and SSR quirks. That’s not just a bug — it’s a sign of weak integration testing. The bigger problem is trust. If an identity provider can’t reliably support mainstream frameworks, it undermines confidence in their entire platform. Developers end up spending more time debugging the SDK than building features. This is why many of us lean toward smaller, well‑maintained libraries (Auth.js, Supabase Auth, etc.). They don’t try to abstract away everything, but they do the fundamentals well — and that’s what matters most in security.
- phendrenad2 10mo agoI'm shocked. Where are all the "SSO companies handle edge cases you can't even imagine" people? It's been 24 hours.
- acessoproibido 10mo agoIf SSO were so easy to solve we wouldn't have a gazillion companies for it. It's probably easy enough if you are a really good engineer, but like 90% working in this industry aren't. Also you ever implemented OAuth2 or shudder SAML? Not how I would like to spend the one life I have been given.
- phendrenad2 10mo agoI think the fact that there are a gazillion companies for it, and they don't compete on security, but instead compete for billboard space in the Mission District of SF and Redwood City California, shows how easy it is to solve.
- acessoproibido 10mo agoI would rather say it shows that no one really cares about security...
- roncesvalles 10mo agoI've been (trying) to use Auth0 over the last few weeks, just as a PoC / "base" app scaffold. My conclusion has been: for social and email login, you don't need things like Auth0. Just write it yourself. You need: session management, account management (you'd already have this), and some simple social login pathways (PKCE etc). If you're an experienced engineer and take the time to do it properly, it's totally fine to "roll your own auth". Things like Auth0 and Firebase Auth are built for nobody and make life more difficult. Any SaaS service that saves you like <40 hours of implementation work is not worth buying into. Just put in the hours and you're set for life. It'll probably take you that many hours to wrangle with integrating it anyway (and when things get serious, you'll need to figure it out down to the bone anyway; auth is not something you can just plop in like a blackbox and forget about it). And if in the process of rolling it yourself you realize "oh shit the service is actually lifting a lot for me", then the time you spent on learning that lesson was also worth it and made you a better engineer. Basically, don't cargo-cult things just because everyone says you should. You should feel the "aha" for why you need to introduce a 3rd party thing.