Elvith Ma'for

Former Reddfugee, found a new home on feddit.de. Server errors made me switch to discuss.tchncs.de. Now finally @ home on feddit.org.

Likes music, tech, programming, board games and video games. Oh… and coffee, lots of coffee!

I � Unicode!

  • 0 Posts
  • 130 Comments
Joined 2 years ago
cake
Cake day: June 21st, 2024

help-circle















  • Yeah, I was reading this and thinking "they have a point, if they refer to talking about a personal project. They might have a point in some place where a simple auth and session cookies are enough.

    Go into a company infrastructure that has a multitude of different systems (first and third party) and also some identity management system and SSO - now we’re closer to the use case of a JWT. There’s a saying “never roll your own crypto” - that somewhat applies to auth as well. There’s so much that can (and will) go wrong.

    They do have a point about token revocation (or the additional round trip for that), but… I’m the scenario above, why would you issue tokens that are valid longer than a day or a few hours??




  • Only downside: Initially the creator of a Flatpack defines how it is sandboxed. For Steam it’s rather permissive. It’s not like on mobile where you get asked for permission for everything potentially dangerous/privacy invading, but rather like the earlier days on mobile where you install a Flatpack and implicitly allow all permissions it wants.

    An update might change the permissions or introduce new ones. You can use tools like Flatseal to change the permissions of installed Flatpack apps, but keep in mind that those changes will probably be gone after the next update and can introduce problems.

    In the end, sandboxing something like Steam is hard, as you not only need to think about Steam’s permissions, but also any game you might run from it…