[HN Gopher] Okta's NextJS-0auth troubles
___________________________________________________________________
Okta's NextJS-0auth troubles
Author : ramimac
Score : 190 points
Date : 2025-11-18 10:17 UTC (2 days ago)
(HTM) web link (joshua.hu)
(TXT) w3m dump (joshua.hu)
| dovys wrote:
| You're either free OSS that gets flooded with AI slop PRs to
| overwhelm maintainers or you're a corporate OSS that uses AI slop
| to frustrate contributors. Are there any positive stories I've
| not seen?
| manithree wrote:
| https://news.ycombinator.com/item?id=45449348
| cedws wrote:
| That's funny. I spotted a similar issue in their Go SDK[1] a few
| years back. I was pretty appalled to see such a basic mistake
| from a security company, but then again it is Okta. [1]:
| https://github.com/okta/okta-sdk-golang/issues/306
| jonathaneunice wrote:
| > I was pretty appalled to see such a basic mistake from a
| security company, but then again it is Okta.
|
| Oh. Em. Gee.
|
| Is this a common take on Okta? The article and comments
| suggest...maybe? That is frightening considering how many
| customers depend on Okta and Auth0.
| parliament32 wrote:
| We evaluated them a while ago but concluded it was amateur-
| hour all the way down. They seem to be one of those classic
| tech companies where 90% of resources go to sales/marketing,
| and engineering remains "minimum viable" hoping they get an
| exit before anyone notices.
| kenhwang wrote:
| I'm convinced Okta's entire business model is undercutting
| everyone with a worse product with worse engineering that
| checks more boxes on the feature page, knowing IT
| procurement people aren't technical and think more
| checkboxes means it's better.
| SAI_Peregrinus wrote:
| Yep. They're an Enterprise(tm) company. That means they
| prioritize features purchasing departments want, not
| functionality.
| Y_Y wrote:
| Okta sucks balls. That's from my perspective as a poor sod
| who's responsible for some sliver of security at this S&P
| listed megacorp that makes its purchasing decisions based on
| golf partners.
| swiftcoder wrote:
| Yeah, I have the misfortune of inheriting a SaaS that built
| on auth0, and the whole stack is rather clownish. But they
| tick all the regulatory boxes, so we're probably stuck with
| them (until they suffer a newsworthy breach, at any rate...)
| hi_hi wrote:
| We've recently moved to Auth0. I'm no security expert. Whats
| the recommended alternative that provides the same features
| and price, but without the risks suggested here?
| Exoristos wrote:
| It's not difficult to implement OAuth2. There are good
| libraries, and even the spec is not complicated. Or use AWS
| Cognito.
| pm90 wrote:
| okta is the worst. Their support is the worst (we always got
| someone overseas who only seemed to understand anything,
| probably they were trained on some corpus) and would take
| forever to loop in anyone that could actually help.
| lq9AJ8yrfs wrote:
| Among the reasons to leave my last job was a CISO and his
| minion who insisted spending $50k+ on Okta for their b2b
| customer and employee authentication was a bulletproof move.
|
| When I brought it up, they said they didn't have anyone smart
| enough to host an identity solution.
|
| They didn't have anyone smart enough to use Okta either. I
| had caught multiple dealbreakers-for-me such dubious /
| conflicting config settings resulting in exposures, actual
| outages caused by forced upgrades, not to mention their
| lackluster responses to bona fide incidents over the years.
|
| I use Authentik for SSO in my homelab, fwiw.
| cookiengineer wrote:
| Kind of funny that stalebots are the new "won't fix"
| methodology to ignore security issues with plausible
| deniability.
| DetroitThrow wrote:
| Security companies that prioritize bugs being sold rather than be
| reported will eventually blow up. Good luck Okta shareholders.
| hypeatei wrote:
| I think GitHub should allow disabling PRs. I don't believe most
| big corporations are interested in dealing with fly-by
| contributions because it might make them look bad or be riddled
| with quality issues.
|
| Also some projects like the Linux kernel are just mirrors and
| would be better off with that functionality disabled.
| jchw wrote:
| While that is true, I feel like it is irrelevant here since it
| seems like Okta definitely wants (and perhaps _needs_ ) the
| fixes. God only knows why GitHub still forces it on though.
| Early on it might've been some mechanism to encourage people to
| accept contributions to push the social coding aspect, but at
| this point I have no idea who this benefits, it mostly confuses
| people when a project doesn't accept PRs.
| hypeatei wrote:
| > Okta definitely wants (and perhaps needs) the fixes
|
| They definitely don't want them if their process requires
| signed commits and their solution is 1) open another PR with
| the authors info then sign it for them, and 2) add AI into
| the mix because git is too hard I guess?
|
| No matter how you slice it, it doesn't seem like there are
| Okta employees who _want_ to be taking changes from third
| parties.
| petre wrote:
| Social on today's Internet = bots and occasionally trolls
| mananaysiempre wrote:
| GitHub actually can natively mark a repo as a mirror (or could?
| I can't find an example now, but they have always been rare).
| The book-with-bookmark icon before "user / repo" in the page
| header is replaced by a mirror-and-reflection-ish-looking
| thing, and the badge after it changes from "Public" to "Public
| mirror". Unfortunately, forcing you into "social coding" (wait,
| is that no longer on the homepage?) takes priority, so that
| mark can only be given out by GitHub staff through manual
| intervention, and it doesn't often happen.
| terminalbraid wrote:
| Maybe the community should use less of github if github doesn't
| provide features the community finds useful.
| jchw wrote:
| IANAL but unfortunately, I think the fix itself shown here might
| be too simple to actually clear the bar for copyright
| eligibility. (And in fairness to copyright law, it is basically
| the only sane way to fix this.) That means that there's probably
| not much you can really do, but I will say this looks fucking
| pathetic, Okta.
| rikafurude21 wrote:
| I'm more confused by the fact that the OP freely submits a PR
| into an open source repo but then wants to use "copyright"
| because the code he submitted ended up being used under the
| wrong name, which was then corrected.
| detaro wrote:
| Why is it confusing to you to expect attribution?
| rikafurude21 wrote:
| thats not the confusing part, its rather confusing to
| threaten to sue for copyright because of mistaken
| attirbution
| cyberpunk wrote:
| He even asked them to force-push a new history because
| they got the name wrong!
|
| Mistakes happen, I guess this hurts his 'commits in a
| public repo' cv score.
| Yasuraka wrote:
| Okta is, if you may excuse my French, straight garbage.
| altairprime wrote:
| And too bad for everyone who was using their former competitor
| Auth0.
| sbmthakur wrote:
| Why if I may ask?
| rcleveng wrote:
| Honestly when I saw Okta in the headline, I had assumed the
| article was going to say they were breached again.
|
| This one is amusing, and as another comment mentioned below,
| large companies are _awful_ at accepting patches on github. Most
| use one-way sync tools to push from their internal repositories
| to github.
| Aldipower wrote:
| WTF is Okta?
| mananaysiempre wrote:
| An auth integrator, a pretty notable one, mostly (originally?)
| OAuth I think. Multiple people calling it a trash fire here
| came as a surprise to me, but I defer to their experience.
| trollbridge wrote:
| Okta was state of the art a decade ago.
| mrweasel wrote:
| Basically an enterprise single sign on solution. We use it to
| allow staff to sign into pretty much any external service using
| Gsuite credentials.
| Traubenfuchs wrote:
| Is there any non shite managed oAuth solution with a free tier
| available?
|
| Auth0 really is super easy and comfortable to integrate and I
| don't want to run my own keycloak or whatever.
| trollbridge wrote:
| Authentik?
| Traubenfuchs wrote:
| > Replace Okta
|
| Aren't they cheeky!
|
| Thanks, I will try.
| theoldgreybeard wrote:
| You couldn't pay me a billion dollars to use Okta.
| pphysch wrote:
| Sadly many people will spend a million dollars to use Okta for
| their 10,000 logins/day (read: <1 tps) instead of running their
| own Keycloak or Authentik or whatever.
|
| OIDC is not scary, and advanced central authorization features
| (beyond group memberships) are a big ole YAGNI / complexity
| trap.
| trollbridge wrote:
| The workload to run Authentik locally is about identical to
| the workload to set up and configure Okta. (Or you could just
| fine someone who will host Authentik for you, if deploying a
| container is too hard for you.)
| p_ing wrote:
| Running your own local AuthN/AuthZ is more than just 'install
| it on a box in the closet'. I don't blame anyone for letting
| one of the giants do this on their behalf -- they have the
| expertise, though I agree I wouldn't touch Okta.
| pphysch wrote:
| For your average enterprise it really is that simple.
| Register some IDPs. Connect a backend. Add some clients
| over time.
|
| Yes, you need someone to wear the IAM admin hat. But once
| you get it configured and running it requires 0.1 FTE or
| less (likely identical to whatever your Okta admin would
| be). Not worth 6+ figures a year and exposure to Okta
| breach risk.
| mrcwinn wrote:
| You just literally saved me one billion dollars. The offer was
| incoming!
| twodave wrote:
| I LOVE LLMs as a learning tool. I HATE LLMs as a communication
| tool. I know, there are people with serious handicaps who benefit
| from LLMs in this area. If only I could talk to those people and
| not wade through all this other garbage.
|
| Especially when the AI is being represented as a person, this to
| me is dishonest. Not to mention annoying, almost more-so than the
| number of different apps that think they are important enough to
| send me push notifications to fill out a survey (don't even get
| me started).
| whichquestion wrote:
| LLMs have definitely helped me reduce my social anxiety when
| writing, especially in a technical work setting. I don't use it
| like the respondent in the article though, I would feel really
| embarassed to not edit an llm's output to be in my own voice.
| But I feel it helps provide me with some structure in whatever
| I'm trying to write when I don't have the mental energy or
| wherewithal to provide it myself.
| RagnarD wrote:
| I've been quite happy with FusionAuth so far. Free to run on your
| own server, easy to understand and set up, easy to program
| against, reliable.
| wingmanjd wrote:
| We're another happy FusionAuth customer. We started with self-
| hosted but just moved to their hosted option this year.
| filearts wrote:
| I think it is distasteful and disrespectful to call out an
| employee by name in this way, regardless of the merit of the rest
| of the OP's post.
| iloveplants wrote:
| well, it was distasteful of to them to close op's pr and apply
| the same patch with improper attribution, and then use ai to
| respond when they were asked about it
| atonse wrote:
| I agree with the parent post that it's distasteful.
|
| There's no value in naming the employee. Whatever that
| employee did, if the company needed to figure out who it was,
| they can from the commit hashes, etc. But there's no value in
| the public knowing the employee's name.
|
| Remember that if someone Googles this person for a newer job,
| it might show up. This is the sort of stuff that can
| disproportionately harm that person's ability to get a job in
| the future, even if they made a small mistake (they even
| apologized for it and was open about what caused it).
|
| So no, it's completely unnecessary and irrelevant to the
| post.
| Exoristos wrote:
| > This is the sort of stuff that can disproportionately
| harm that person's ability to get a job in the future.
|
| Isn't that beneficial in this case?
| Freak_NL wrote:
| > Remember that if someone Googles this person for a newer
| job, it might show up.
|
| Not to sound too harsh, but this is a person who rudely let
| AI perform a task badly which should have been handled by
| just... merging/rebasing the PR after confirming it does
| what it should do, _then_ couldn 't be bothered to reply
| and instead let the robot handle it, and _then_ refused to
| fix the mess they made (making the apology void).
|
| That's three strikes.
| abraae wrote:
| What if it's some junior given a job beyond their
| abilities, and struggling manfully using whatever tools
| they have to hand. Is it worth publicly trashing their
| name? What does their name really add to this article?
| technion wrote:
| I agree what occurred is quite egregious. But "use ai to
| talk to customers" and "play games with signed commits"
| sound much more like corporate policy than one employees
| mistake.
| parliament32 wrote:
| > Remember that if someone Googles this person for a newer
| job, it might show up.
|
| That's the whole point; I sincerely hope it does. Why would
| anyone want to hire someone that delegates their core job
| to a slop generator?
| DrammBA wrote:
| I don't think it is distasteful or disrespectful, he's just
| explaining what happened and why, and he's obviously unhappy
| with the whole ordeal.
| merrvk wrote:
| They maintain a public repo.
| avree wrote:
| FWIW, the employee reply (who the author is putting on blast)
| seems like it was written by a human, not an AI.
|
| "You're absolutely right!" is the Claude cliche (not a ChatGPT
| one) - "You are absolutely correct." is not that.
| DrammBA wrote:
| Directly from the employee (tusharpandey13) in the github PR:
|
| > Yeah, i had to manually stop it and delete the ai-generated
| comment.
| DrammBA wrote:
| I find it funny that this seemingly fictitious person Simen A. W.
| Olsen my@simen.io will forever be engraved as a co-author of a
| one-line change in the nextjs-auth0 repo.
| letmetweakit wrote:
| https://who.is/whois/simen.io
|
| He's not fictitious I think.
| merrvk wrote:
| That maintainer seems clueless
| fudged71 wrote:
| I'm currently building on the Auth0 SaaStarter because it seemed
| to be the only option in the market for something with all the
| core features enterprises are looking for. Is there an
| alternative that doesn't require building from scratch?
___________________________________________________________________
(page generated 2025-11-20 23:00 UTC)