Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Unfortunately, OAuth relies on them. Many SaaS offerings rely on OAuth.


SAML and some oauth flavors do, but most of oauth does not.


I don't think OAuth requires third-party cookies, and SAML definitely does not. The authentication parts use HTTP POSTs or redirects from the IdP to SP. You probably do want cookies to track the sessions on each end, but those would be first-party.

It's possible for your IdP to track the SPs you authenticate to regardless of protocol or cookie use, of course.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: