[HN Gopher] Okta's NextJS-0auth troubles
       ___________________________________________________________________
        
       Okta's NextJS-0auth troubles
        
       Author : ramimac
       Score  : 190 points
       Date   : 2025-11-18 10:17 UTC (2 days ago)
        
 (HTM) web link (joshua.hu)
 (TXT) w3m dump (joshua.hu)
        
       | dovys wrote:
       | You're either free OSS that gets flooded with AI slop PRs to
       | overwhelm maintainers or you're a corporate OSS that uses AI slop
       | to frustrate contributors. Are there any positive stories I've
       | not seen?
        
         | manithree wrote:
         | https://news.ycombinator.com/item?id=45449348
        
       | cedws wrote:
       | That's funny. I spotted a similar issue in their Go SDK[1] a few
       | years back. I was pretty appalled to see such a basic mistake
       | from a security company, but then again it is Okta. [1]:
       | https://github.com/okta/okta-sdk-golang/issues/306
        
         | jonathaneunice wrote:
         | > I was pretty appalled to see such a basic mistake from a
         | security company, but then again it is Okta.
         | 
         | Oh. Em. Gee.
         | 
         | Is this a common take on Okta? The article and comments
         | suggest...maybe? That is frightening considering how many
         | customers depend on Okta and Auth0.
        
           | parliament32 wrote:
           | We evaluated them a while ago but concluded it was amateur-
           | hour all the way down. They seem to be one of those classic
           | tech companies where 90% of resources go to sales/marketing,
           | and engineering remains "minimum viable" hoping they get an
           | exit before anyone notices.
        
             | kenhwang wrote:
             | I'm convinced Okta's entire business model is undercutting
             | everyone with a worse product with worse engineering that
             | checks more boxes on the feature page, knowing IT
             | procurement people aren't technical and think more
             | checkboxes means it's better.
        
           | SAI_Peregrinus wrote:
           | Yep. They're an Enterprise(tm) company. That means they
           | prioritize features purchasing departments want, not
           | functionality.
        
           | Y_Y wrote:
           | Okta sucks balls. That's from my perspective as a poor sod
           | who's responsible for some sliver of security at this S&P
           | listed megacorp that makes its purchasing decisions based on
           | golf partners.
        
           | swiftcoder wrote:
           | Yeah, I have the misfortune of inheriting a SaaS that built
           | on auth0, and the whole stack is rather clownish. But they
           | tick all the regulatory boxes, so we're probably stuck with
           | them (until they suffer a newsworthy breach, at any rate...)
        
           | hi_hi wrote:
           | We've recently moved to Auth0. I'm no security expert. Whats
           | the recommended alternative that provides the same features
           | and price, but without the risks suggested here?
        
             | Exoristos wrote:
             | It's not difficult to implement OAuth2. There are good
             | libraries, and even the spec is not complicated. Or use AWS
             | Cognito.
        
           | pm90 wrote:
           | okta is the worst. Their support is the worst (we always got
           | someone overseas who only seemed to understand anything,
           | probably they were trained on some corpus) and would take
           | forever to loop in anyone that could actually help.
        
           | lq9AJ8yrfs wrote:
           | Among the reasons to leave my last job was a CISO and his
           | minion who insisted spending $50k+ on Okta for their b2b
           | customer and employee authentication was a bulletproof move.
           | 
           | When I brought it up, they said they didn't have anyone smart
           | enough to host an identity solution.
           | 
           | They didn't have anyone smart enough to use Okta either. I
           | had caught multiple dealbreakers-for-me such dubious /
           | conflicting config settings resulting in exposures, actual
           | outages caused by forced upgrades, not to mention their
           | lackluster responses to bona fide incidents over the years.
           | 
           | I use Authentik for SSO in my homelab, fwiw.
        
         | cookiengineer wrote:
         | Kind of funny that stalebots are the new "won't fix"
         | methodology to ignore security issues with plausible
         | deniability.
        
       | DetroitThrow wrote:
       | Security companies that prioritize bugs being sold rather than be
       | reported will eventually blow up. Good luck Okta shareholders.
        
       | hypeatei wrote:
       | I think GitHub should allow disabling PRs. I don't believe most
       | big corporations are interested in dealing with fly-by
       | contributions because it might make them look bad or be riddled
       | with quality issues.
       | 
       | Also some projects like the Linux kernel are just mirrors and
       | would be better off with that functionality disabled.
        
         | jchw wrote:
         | While that is true, I feel like it is irrelevant here since it
         | seems like Okta definitely wants (and perhaps _needs_ ) the
         | fixes. God only knows why GitHub still forces it on though.
         | Early on it might've been some mechanism to encourage people to
         | accept contributions to push the social coding aspect, but at
         | this point I have no idea who this benefits, it mostly confuses
         | people when a project doesn't accept PRs.
        
           | hypeatei wrote:
           | > Okta definitely wants (and perhaps needs) the fixes
           | 
           | They definitely don't want them if their process requires
           | signed commits and their solution is 1) open another PR with
           | the authors info then sign it for them, and 2) add AI into
           | the mix because git is too hard I guess?
           | 
           | No matter how you slice it, it doesn't seem like there are
           | Okta employees who _want_ to be taking changes from third
           | parties.
        
           | petre wrote:
           | Social on today's Internet = bots and occasionally trolls
        
         | mananaysiempre wrote:
         | GitHub actually can natively mark a repo as a mirror (or could?
         | I can't find an example now, but they have always been rare).
         | The book-with-bookmark icon before "user / repo" in the page
         | header is replaced by a mirror-and-reflection-ish-looking
         | thing, and the badge after it changes from "Public" to "Public
         | mirror". Unfortunately, forcing you into "social coding" (wait,
         | is that no longer on the homepage?) takes priority, so that
         | mark can only be given out by GitHub staff through manual
         | intervention, and it doesn't often happen.
        
         | terminalbraid wrote:
         | Maybe the community should use less of github if github doesn't
         | provide features the community finds useful.
        
       | jchw wrote:
       | IANAL but unfortunately, I think the fix itself shown here might
       | be too simple to actually clear the bar for copyright
       | eligibility. (And in fairness to copyright law, it is basically
       | the only sane way to fix this.) That means that there's probably
       | not much you can really do, but I will say this looks fucking
       | pathetic, Okta.
        
         | rikafurude21 wrote:
         | I'm more confused by the fact that the OP freely submits a PR
         | into an open source repo but then wants to use "copyright"
         | because the code he submitted ended up being used under the
         | wrong name, which was then corrected.
        
           | detaro wrote:
           | Why is it confusing to you to expect attribution?
        
             | rikafurude21 wrote:
             | thats not the confusing part, its rather confusing to
             | threaten to sue for copyright because of mistaken
             | attirbution
        
               | cyberpunk wrote:
               | He even asked them to force-push a new history because
               | they got the name wrong!
               | 
               | Mistakes happen, I guess this hurts his 'commits in a
               | public repo' cv score.
        
       | Yasuraka wrote:
       | Okta is, if you may excuse my French, straight garbage.
        
         | altairprime wrote:
         | And too bad for everyone who was using their former competitor
         | Auth0.
        
         | sbmthakur wrote:
         | Why if I may ask?
        
       | rcleveng wrote:
       | Honestly when I saw Okta in the headline, I had assumed the
       | article was going to say they were breached again.
       | 
       | This one is amusing, and as another comment mentioned below,
       | large companies are _awful_ at accepting patches on github. Most
       | use one-way sync tools to push from their internal repositories
       | to github.
        
       | Aldipower wrote:
       | WTF is Okta?
        
         | mananaysiempre wrote:
         | An auth integrator, a pretty notable one, mostly (originally?)
         | OAuth I think. Multiple people calling it a trash fire here
         | came as a surprise to me, but I defer to their experience.
        
           | trollbridge wrote:
           | Okta was state of the art a decade ago.
        
         | mrweasel wrote:
         | Basically an enterprise single sign on solution. We use it to
         | allow staff to sign into pretty much any external service using
         | Gsuite credentials.
        
       | Traubenfuchs wrote:
       | Is there any non shite managed oAuth solution with a free tier
       | available?
       | 
       | Auth0 really is super easy and comfortable to integrate and I
       | don't want to run my own keycloak or whatever.
        
         | trollbridge wrote:
         | Authentik?
        
           | Traubenfuchs wrote:
           | > Replace Okta
           | 
           | Aren't they cheeky!
           | 
           | Thanks, I will try.
        
       | theoldgreybeard wrote:
       | You couldn't pay me a billion dollars to use Okta.
        
         | pphysch wrote:
         | Sadly many people will spend a million dollars to use Okta for
         | their 10,000 logins/day (read: <1 tps) instead of running their
         | own Keycloak or Authentik or whatever.
         | 
         | OIDC is not scary, and advanced central authorization features
         | (beyond group memberships) are a big ole YAGNI / complexity
         | trap.
        
           | trollbridge wrote:
           | The workload to run Authentik locally is about identical to
           | the workload to set up and configure Okta. (Or you could just
           | fine someone who will host Authentik for you, if deploying a
           | container is too hard for you.)
        
           | p_ing wrote:
           | Running your own local AuthN/AuthZ is more than just 'install
           | it on a box in the closet'. I don't blame anyone for letting
           | one of the giants do this on their behalf -- they have the
           | expertise, though I agree I wouldn't touch Okta.
        
             | pphysch wrote:
             | For your average enterprise it really is that simple.
             | Register some IDPs. Connect a backend. Add some clients
             | over time.
             | 
             | Yes, you need someone to wear the IAM admin hat. But once
             | you get it configured and running it requires 0.1 FTE or
             | less (likely identical to whatever your Okta admin would
             | be). Not worth 6+ figures a year and exposure to Okta
             | breach risk.
        
         | mrcwinn wrote:
         | You just literally saved me one billion dollars. The offer was
         | incoming!
        
       | twodave wrote:
       | I LOVE LLMs as a learning tool. I HATE LLMs as a communication
       | tool. I know, there are people with serious handicaps who benefit
       | from LLMs in this area. If only I could talk to those people and
       | not wade through all this other garbage.
       | 
       | Especially when the AI is being represented as a person, this to
       | me is dishonest. Not to mention annoying, almost more-so than the
       | number of different apps that think they are important enough to
       | send me push notifications to fill out a survey (don't even get
       | me started).
        
         | whichquestion wrote:
         | LLMs have definitely helped me reduce my social anxiety when
         | writing, especially in a technical work setting. I don't use it
         | like the respondent in the article though, I would feel really
         | embarassed to not edit an llm's output to be in my own voice.
         | But I feel it helps provide me with some structure in whatever
         | I'm trying to write when I don't have the mental energy or
         | wherewithal to provide it myself.
        
       | RagnarD wrote:
       | I've been quite happy with FusionAuth so far. Free to run on your
       | own server, easy to understand and set up, easy to program
       | against, reliable.
        
         | wingmanjd wrote:
         | We're another happy FusionAuth customer. We started with self-
         | hosted but just moved to their hosted option this year.
        
       | filearts wrote:
       | I think it is distasteful and disrespectful to call out an
       | employee by name in this way, regardless of the merit of the rest
       | of the OP's post.
        
         | iloveplants wrote:
         | well, it was distasteful of to them to close op's pr and apply
         | the same patch with improper attribution, and then use ai to
         | respond when they were asked about it
        
           | atonse wrote:
           | I agree with the parent post that it's distasteful.
           | 
           | There's no value in naming the employee. Whatever that
           | employee did, if the company needed to figure out who it was,
           | they can from the commit hashes, etc. But there's no value in
           | the public knowing the employee's name.
           | 
           | Remember that if someone Googles this person for a newer job,
           | it might show up. This is the sort of stuff that can
           | disproportionately harm that person's ability to get a job in
           | the future, even if they made a small mistake (they even
           | apologized for it and was open about what caused it).
           | 
           | So no, it's completely unnecessary and irrelevant to the
           | post.
        
             | Exoristos wrote:
             | > This is the sort of stuff that can disproportionately
             | harm that person's ability to get a job in the future.
             | 
             | Isn't that beneficial in this case?
        
             | Freak_NL wrote:
             | > Remember that if someone Googles this person for a newer
             | job, it might show up.
             | 
             | Not to sound too harsh, but this is a person who rudely let
             | AI perform a task badly which should have been handled by
             | just... merging/rebasing the PR after confirming it does
             | what it should do, _then_ couldn 't be bothered to reply
             | and instead let the robot handle it, and _then_ refused to
             | fix the mess they made (making the apology void).
             | 
             | That's three strikes.
        
               | abraae wrote:
               | What if it's some junior given a job beyond their
               | abilities, and struggling manfully using whatever tools
               | they have to hand. Is it worth publicly trashing their
               | name? What does their name really add to this article?
        
               | technion wrote:
               | I agree what occurred is quite egregious. But "use ai to
               | talk to customers" and "play games with signed commits"
               | sound much more like corporate policy than one employees
               | mistake.
        
             | parliament32 wrote:
             | > Remember that if someone Googles this person for a newer
             | job, it might show up.
             | 
             | That's the whole point; I sincerely hope it does. Why would
             | anyone want to hire someone that delegates their core job
             | to a slop generator?
        
         | DrammBA wrote:
         | I don't think it is distasteful or disrespectful, he's just
         | explaining what happened and why, and he's obviously unhappy
         | with the whole ordeal.
        
         | merrvk wrote:
         | They maintain a public repo.
        
       | avree wrote:
       | FWIW, the employee reply (who the author is putting on blast)
       | seems like it was written by a human, not an AI.
       | 
       | "You're absolutely right!" is the Claude cliche (not a ChatGPT
       | one) - "You are absolutely correct." is not that.
        
         | DrammBA wrote:
         | Directly from the employee (tusharpandey13) in the github PR:
         | 
         | > Yeah, i had to manually stop it and delete the ai-generated
         | comment.
        
       | DrammBA wrote:
       | I find it funny that this seemingly fictitious person Simen A. W.
       | Olsen my@simen.io will forever be engraved as a co-author of a
       | one-line change in the nextjs-auth0 repo.
        
         | letmetweakit wrote:
         | https://who.is/whois/simen.io
         | 
         | He's not fictitious I think.
        
       | merrvk wrote:
       | That maintainer seems clueless
        
       | fudged71 wrote:
       | I'm currently building on the Auth0 SaaStarter because it seemed
       | to be the only option in the market for something with all the
       | core features enterprises are looking for. Is there an
       | alternative that doesn't require building from scratch?
        
       ___________________________________________________________________
       (page generated 2025-11-20 23:00 UTC)