stacks-archive / app-mining

For App Mining landing page development and App Mining operations.
https://app.co/mining
MIT License
49 stars 16 forks source link

SimpleID Usage Qualifcation #141

Closed polluterofminds closed 4 years ago

polluterofminds commented 4 years ago

I'm forgoing the template here because this is not an App Mining improvement proposal. It's an independent authentication system built using Blockstack Auth and there needs to be an official determination as to whether applications can use this and be eligible for App Mining.

Please see Forum thread for more details:

https://forum.blockstack.org/t/simple-id-easier-blockstack-feature-survey/8476/26

Expected results from this issue:

  1. Approve or reject SimpleID as an allowable authentication solution in App Mining apps.

  2. If rejected, specify the exact reasons why so that the community may have a voice in the discussion.

0xpbj commented 4 years ago

Also, @larrysalibra - can we get your input on if NIL will penalize apps if they add SimpleID as an alternative auth option?

friedger commented 4 years ago

See also #100

friedger commented 4 years ago

As simple ID is unoptionated maybe some guidelines are needed in order to be eligible.

polluterofminds commented 4 years ago

Guidelines for whom? SimpleID or the app developers using it? When we say SimpleID is un-opinionated, what we mean is that we don't think developer tools should force developers down one path or another. Decentralization means choices.

friedger commented 4 years ago

I was thinking of guide lines how developers need to present the authentication. Maybe that is against your un-opinionated vision.

On Tue, 6 Aug 2019, 19:14 Justin Hunter, notifications@github.com wrote:

Guidelines for whom? SimpleID or the app developers using it? When we say SimpleID is un-opinionated, what we mean is that we don't think developer tools should force developers down one path or another. Decentralization means choices.

— You are receiving this because you commented. Reply to this email directly, view it on GitHub https://github.com/blockstack/app-mining/issues/141?email_source=notifications&email_token=AALBYWKOW3C7DTL6FQPTWEDQDGWQFA5CNFSM4IJXW5P2YY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGOD3V222A#issuecomment-518761832, or mute the thread https://github.com/notifications/unsubscribe-auth/AALBYWKAU6IGE3E46I5MHO3QDGWQFANCNFSM4IJXW5PQ .

0xpbj commented 4 years ago

See tech docs with more details here: https://github.com/simplesecure/ssa-sdk/blob/master/TECHNICAL_DOCS.md

polluterofminds commented 4 years ago

@friedger No, I think you're right. If there's a concern that users aren't going to be notified of how this works, Blockstack has every right to ask App Developers to do so in some way. That's the flexibility this affords though. Each developer can communicate however they see fit and still land on the same message.

larrysalibra commented 4 years ago

NIL would treat SimpleID the same as any other 3rd party auth system.

stackatron commented 4 years ago

Agree with @larrysalibra. Moving to review.

friedger commented 4 years ago

@jeffdomke The decision here does not match with what @cuevasm said in https://github.com/blockstack/app-mining/issues/148#issuecomment-534395693

Please reopen!