curved-ram-6189
11/29/2023, 2:42 PMicy-manchester-83109
11/29/2023, 4:34 PMicy-manchester-83109
11/29/2023, 4:35 PMcurved-ram-6189
11/29/2023, 5:42 PMicy-manchester-83109
11/29/2023, 5:53 PMcurved-ram-6189
11/29/2023, 6:32 PMcurved-ram-6189
11/29/2023, 6:32 PMicy-manchester-83109
11/29/2023, 6:36 PMicy-manchester-83109
11/29/2023, 6:37 PMcurved-ram-6189
11/29/2023, 6:40 PMcurved-ram-6189
11/29/2023, 6:41 PMicy-manchester-83109
11/29/2023, 7:01 PMicy-manchester-83109
11/29/2023, 7:06 PM... how to do simple things an idp should be able to do
The great thing about ory products is that they focus on particular concerns related to "things" people tend to see (for historical reasons) in an IdP. That approach gives you freedom and flexibility no idp out there can offer. But you lose "expected convenience". The available services provide those "things", but in a different way and they force you to think about what you need and how you need those.
curved-ram-6189
11/29/2023, 7:58 PMicy-manchester-83109
11/29/2023, 8:02 PMicy-manchester-83109
11/29/2023, 8:04 PM... do things like role determination or scope mapping.This is out of scope for OAuth2 and OIDC but this is what all idp solutions out there try to sell you. Roles have nothing in common with scopes. Roles are about user authorization. Scopes are about client authorization. If you try abusing scopes for that - wish you fun 😉