Community
Chat Logs
Wednesday, March 18, 2026
- dreamrealkotauth.text=a self-hosted OAuth2/OIDC authentication platform built on Kotlin/Ktor, targeting the gap between Keycloak's configuration weight and Auth0's pricing ceiling. Single Docker image, PostgreSQL backend, multi-tenancy, RBAC, MFA, social login, and a framework-free domain layer.
- nevetok, dreamreal: updated kotauth.
- dreamrealkotauth.urls=https://github.com/InumanSoul/kotauth
- nevetok, dreamreal: updated kotauth.
- dreamrealkotauth.seealso=ktor,exposed,oauth2,oidc,authentication,authorization
- nevetok, dreamreal: updated kotauth.
- dreamrealkotauth.tags=kotlin,auth,oidc,oauth2,self-hosted
- nevetok, dreamreal: updated kotauth.
- dreamrealktor.text=a Kotlin-native async web framework from JetBrains. Coroutine-first, lightweight, and deliberately unopinionated about structure. Handles both server and client HTTP. Not a Spring replacement; a different shape of tool.
- nevetok, dreamreal: updated ktor.
- dreamrealktor.urls=https://ktor.io
- nevetok, dreamreal: updated ktor.
- dreamrealktor.seealso=exposed,kotlin
- nevetok, dreamreal: updated ktor.
- dreamrealktor.tags=kotlin,web,framework,jetbrains
- nevetok, dreamreal: updated ktor.
- dreamrealexposed.text=JetBrains' Kotlin SQL framework, offering a type-safe DSL for query construction and a lightweight DAO layer. Sits closer to the SQL than most ORMs โ you're meant to know what's being executed.
- nevetok, dreamreal: updated exposed.
- dreamrealexposed.urls=https://github.com/JetBrains/Exposed
- nevetok, dreamreal: updated exposed.
- dreamrealexposed.seealso=ktor,kotlin
- nevetok, dreamreal: updated exposed.
- dreamrealexposed.tags=kotlin,sql,orm,jetbrains
- nevetok, dreamreal: updated exposed.
- dreamrealauthentication.text=the problem of verifying identity: confirming that a principal is who they claim to be. Typically resolved via credentials, tokens, certificates, or biometrics. Precedes authorization and is a distinct concern โ conflating the two is a common source of security design debt.
- nevetok, dreamreal: updated authentication.
- dreamrealauthentication.seealso=authorization,oauth2,oidc
- nevetok, dreamreal: updated authentication.
- dreamrealauthentication.tags=security,auth,identity
- nevetok, dreamreal: updated authentication.
- dreamrealauthorization.text=the problem of verifying permission: confirming that an authenticated principal may perform a given action on a given resource. RBAC, ABAC, and policy engines like OPA are common patterns. Authorization logic is where most access control bugs live.
- nevetok, dreamreal: updated authorization.
- dreamrealauthorization.seealso=authentication,oauth2,oidc
- nevetok, dreamreal: updated authorization.
- dreamrealauthorization.tags=security,auth,access-control
- nevetok, dreamreal: updated authorization.
- dreamrealoauth2.text=an authorization delegation framework (RFC 6749) allowing a resource owner to grant a third party limited access to their resources without sharing credentials. Not an authentication protocol on its own โ that's a common misuse. Issues access tokens; token shape and semantics are left to the implementation.
- nevetok, dreamreal: updated oauth2.
- dreamrealoauth2.urls=https://oauth.net/2/
- nevetok, dreamreal: updated oauth2.
- dreamrealoauth2.seealso=oidc,authentication,authorization
- nevetok, dreamreal: updated oauth2.
- dreamrealoauth2.tags=security,auth,rfc,standard
- nevetok, dreamreal: updated oauth2.
- dreamrealoidc.text=OpenID Connect, an identity layer built on top of OAuth2. Adds the ID token (a JWT), a UserInfo endpoint, and standardized claims โ the parts OAuth2 deliberately left out. The current industry standard for federated authentication.
- nevetok, dreamreal: updated oidc.
- dreamrealoidc.urls=https://openid.net/connect/
- nevetok, dreamreal: updated oidc.
- dreamrealoidc.seealso=oauth2,authentication,authorization
- nevetok, dreamreal: updated oidc.
- dreamrealoidc.tags=security,auth,identity,standard
- nevetok, dreamreal: updated oidc.
- dreamrealcomprehension debt=<reply>Comprehension debt is the gap between expectations and understanding created when developers let AI do design and implementation. It's far worse than technical debt as an attribute of your codebase.
- nevetok, dreamreal: updated comprehension debt.
- dreamrealtechnical debt<reply>Tech debt is a description of the cost to maintain a system that has external dependencies. You *depend* on Spring to do things a certain way, and if Spring changes, then you *have* to change with it, and you inherit the weaknesses of your dependencies as well.
- nevetok, dreamreal: updated technical debt<reply>tech debt.
- dreamrealcomprehension debt.seealso=technical debt
- nevetok, dreamreal: updated comprehension debt.
- * nevet joined #streampack