HN user

EtienneK

1,190 karma

I'm a South African that likes to think of myself as a Tinkerer, Hacker, Gamer, Thinker and Follower of Jesus.

http://www.etiennek.com

[ my public key: https://keybase.io/etiennek; my proof: https://keybase.io/etiennek/sigs/iHxgJybSqL6QX6ijCsTHklYxcroKp1F9pJh1vtyuFNc ]

Posts30
Comments178
View on HN
ioplus.nl 6mo ago

Cloudflare threatens Italy exit over €14M fine

EtienneK
1pts1
www.phoronix.com 6mo ago

Canonical Builds Steam Snap for Ubuntu ARM64 Leveraging FEX

EtienneK
2pts0
www.keycloak.org 1y ago

Keycloak: Open-Source Identity and Access Management

EtienneK
3pts0
idpro.org 2y ago

IDPro Body of Knowledge

EtienneK
2pts0
epicenter.works 2y ago

EU Digital Identity Reform: The Good, Bad and Ugly in the EIDAS Regulation

EtienneK
66pts45
github.com 2y ago

OpenFGA: A high performance and flexible authorization/permission engine

EtienneK
2pts0
old.reddit.com 3y ago

Creating a Jump Host in 2023

EtienneK
1pts0
lockstep.com.au 3y ago

On Sovereignty and Identity

EtienneK
1pts0
developer.apple.com 4y ago

Passkeys

EtienneK
1pts0
openid.net 4y ago

OpenID for Verifiable Credentials [pdf]

EtienneK
2pts0
www.digimeeple.com 5y ago

List of Xbox Games That Support Mouse and Keyboard

EtienneK
1pts0
techcommunity.microsoft.com 5y ago

Ion – open, public, permissionless ID network that runs atop Bitcoin

EtienneK
3pts2
www.gethalfmoon.com 5y ago

Halfmoon – A beautiful front-end framework with a built-in dark mode

EtienneK
2pts0
kotaku.com 5y ago

The Cyberpunk 2077 review drama

EtienneK
8pts0
www.theatlantic.com 6y ago

The Extraordinary Decisions Facing Italian Doctors

EtienneK
4pts0
9to5mac.com 6y ago

Finally Apple Joins Fido Alliance

EtienneK
2pts0
youtu.be 6y ago

Electric vs. Hydrogen – James May reviews his own cars

EtienneK
1pts0
gist.github.com 7y ago

Call for Kotlin as a major front end language

EtienneK
1pts0
www.bloomberg.com 7y ago

Wall Street’s Latest Secretive Trend? Board Game Nights

EtienneK
1pts0
thenewstack.io 8y ago

How Synchronous REST Turns Microservices Back into Monoliths (2016)

EtienneK
1pts0
www.etiennek.com 9y ago

Every Technology Problem Is First a Political Problem

EtienneK
1pts0
medium.com 9y ago

The rebellion against the inner circle of no-skin-in-the-game “clerks”

EtienneK
1pts0
fivethirtyeight.com 10y ago

Crowdfunding Is Driving a Board Game Renaissance

EtienneK
82pts39
t37.net 11y ago

Is Docker ready for production?

EtienneK
155pts70
isizulu.net 12y ago

Open this link in Chrome...

EtienneK
3pts2
mobile.theverge.com 12y ago

Game of Thrones piracy is "better than an Emmy"

EtienneK
10pts1
hn.premii.com 12y ago

Hacker News Web App for Mobile

EtienneK
239pts160
buildnewgames.com 14y ago

Real Time Multiplayer in HTML5

EtienneK
150pts60
www.coincrate.com 14y ago

Show HN: Coincrate.com - Love video games? Share it with the world

EtienneK
1pts0
www.etiennek.com 14y ago

Steering Behaviours on an HTML 5 Canvas

EtienneK
1pts0

Most people understand these two things to be, collectively, the "provider" side of OAuth

Citation needed. As another commenter already noted, the term "Provider" is rarely used in OAuth itself. When it is mentioned, it's typically in the context of OpenID Connect, where it refers specifically to the Authorization Server - not the Resource Server.

the service provider, who is providing an API that requires authorization

That’s actually the Resource Server.

I understand that the current MCP spec [1] merges the Authorization Server and Resource Server roles, similar to what your library does. However, there are strong reasons to keep these roles separate [2].

In fact, the MCP spec authors acknowledge this [3], and the latest draft [4] makes implementing an Authorization Server optional for MCP services.

That’s why I’m being particular about clearly naming the roles your library supports in the OAuth flow. Going forward, MCP servers will always act as OAuth Resource Servers, but will only optionally act as Authorization Servers. Your library should make that distinction explicit.

[1] https://modelcontextprotocol.io/specification/2025-03-26/bas...

[2] https://aaronparecki.com/2025/04/03/15/oauth-for-model-conte...

[3] https://github.com/modelcontextprotocol/modelcontextprotocol...

[4] https://modelcontextprotocol.io/specification/draft/basic/au...

This is a TypeScript library that implements the provider side of the OAuth 2.1 protocol with PKCE support.

What is the "provider" side? OAuth 2.1 has no definition of a "provider". Is this for Clients? Resource Servers? Authorization Server?

Quickly skimming the rest of the README it seems this is for creating a mix of a Client and a Resource Server, but I could be mistaken.

To emphasize, this is not "vibe coded". Every line was thoroughly reviewed and cross-referenced with relevant RFCs, by security experts with previous experience with those RFCs

Experience with the RFCs but have not been able to correctly name it.

Ah, the iPad Pro: One of the most compact and powerful computing devices of all time. But trying to use even a small fraction of that power requires workarounds like this.

I bought into the idea of the iPad Pro as a coding device 4 years ago; only to have been left very disappointed. And it seems nothing has really changed (although the M series iPads do at least support full screen external monitors now - mine still has black bars).

I won't consider an iPad Pro until I can actually use it as a development laptop replacement. I still see use for the non-pro iPads in my life; but not the Pro.

I also watched something on the Quest 3 using the Amazon Prime Video app the other day. It was a cool experience, but for now, I still find a TV better. This might change as the technology improves.

Which is why I find the choice not to release an app for the Apple VP odd: it has better hardware so the experience should also be better. Maybe it's because they expect the VP to sell a lot less than the Quest 3?

Yes, exactly! These new integrated graphics chips are great for 1080p 60hz for the games kids actually play, like Minecraft, Roblox, Fortnite, CSGO, etc.

Integrate graphics will be the default in the future with discrete GPUs used only by the niche gamers and AI developer.

Lowest common denominator consoles like the Series S and Steam Deck are also contributing to this push as gamedevs are forced to optimize for integrated AMD graphics.