Okta's NextJS-0auth troubles

joshua.hu

199 points by ramimac 3 days ago


deepsun - 5 minutes ago

Okta requiring to create a video for a pretty obvious vulnerability shows that Okta does not take security seriously, contrary to what they say at their earnings calls. Sounds like deceiving their investors.

cedws - 2 days ago

That’s funny. I spotted a similar issue in their Go SDK[1] a few years back. I was pretty appalled to see such a basic mistake from a security company, but then again it is Okta. [1]: https://github.com/okta/okta-sdk-golang/issues/306

prodigycorp - 16 minutes ago

I used Auth0's Nextjs package for a previous application I built. Auth0 seemed really tempting to use at first glance – support for lots of languages, lots of marketing, and lots of features. It reality, it was a nightmare to use because its documentation is bad and there are a whole host of edge case bugs that never seem to make its way out of auth0 forums and into an actual PR.

Yasuraka - 5 hours ago

Okta is, if you may excuse my French, straight garbage.

hypeatei - 5 hours ago

I think GitHub should allow disabling PRs. I don't believe most big corporations are interested in dealing with fly-by contributions because it might make them look bad or be riddled with quality issues.

Also some projects like the Linux kernel are just mirrors and would be better off with that functionality disabled.

filearts - 4 hours ago

I think it is distasteful and disrespectful to call out an employee by name in this way, regardless of the merit of the rest of the OP's post.

theoldgreybeard - 5 hours ago

You couldn't pay me a billion dollars to use Okta.

fudged71 - 2 hours ago

I'm currently building on the Auth0 SaaStarter because it seemed to be the only option in the market for something with all the core features enterprises are looking for. Is there an alternative that doesn't require building from scratch?

DrammBA - 2 hours ago

I find it funny that this seemingly fictitious person Simen A. W. Olsen my@simen.io will forever be engraved as a co-author of a one-line change in the nextjs-auth0 repo.

rcleveng - 5 hours ago

Honestly when I saw Okta in the headline, I had assumed the article was going to say they were breached again.

This one is amusing, and as another comment mentioned below, large companies are awful at accepting patches on github. Most use one-way sync tools to push from their internal repositories to github.

RagnarD - 4 hours ago

I've been quite happy with FusionAuth so far. Free to run on your own server, easy to understand and set up, easy to program against, reliable.

- an hour ago
[deleted]
jchw - 5 hours ago

IANAL but unfortunately, I think the fix itself shown here might be too simple to actually clear the bar for copyright eligibility. (And in fairness to copyright law, it is basically the only sane way to fix this.) That means that there's probably not much you can really do, but I will say this looks fucking pathetic, Okta.

merrvk - 2 hours ago

That maintainer seems clueless

avree - 3 hours ago

FWIW, the employee reply (who the author is putting on blast) seems like it was written by a human, not an AI.

"You're absolutely right!" is the Claude cliche (not a ChatGPT one) - "You are absolutely correct." is not that.

twodave - 5 hours ago

I LOVE LLMs as a learning tool. I HATE LLMs as a communication tool. I know, there are people with serious handicaps who benefit from LLMs in this area. If only I could talk to those people and not wade through all this other garbage.

Especially when the AI is being represented as a person, this to me is dishonest. Not to mention annoying, almost more-so than the number of different apps that think they are important enough to send me push notifications to fill out a survey (don’t even get me started).

dovys - 2 days ago

You're either free OSS that gets flooded with AI slop PRs to overwhelm maintainers or you're a corporate OSS that uses AI slop to frustrate contributors. Are there any positive stories I've not seen?

Traubenfuchs - 5 hours ago

Is there any non shite managed oAuth solution with a free tier available?

Auth0 really is super easy and comfortable to integrate and I don‘t want to run my own keycloak or whatever.

DetroitThrow - 6 hours ago

Security companies that prioritize bugs being sold rather than be reported will eventually blow up. Good luck Okta shareholders.

yahoozoo - an hour ago

[dead]

Will-Reppeto - 5 hours ago

[flagged]

Brian-Watkins - 3 hours ago

[flagged]

Aldipower - 5 hours ago

WTF is Okta?