I believe I've read that authentication should be ...
# cfml-general
b
I believe I've read that authentication should be done during onSessionStart which, at first glance, makes sense. Authenticate them at the beginning of their session and then not have to bother checking again. However, when using an enterprise SSO, if they were to sign out on another device or application, wouldn't the onSessionStart auth allow them, and possibly someone else, to erroneously remain authenticated? In which case, wouldn't putting the auth in onRequestStart be more secure? Yes, there would be a performance tradeoff, but I would think security would trump that.
p
OhRequestStart would be your ideal point for handling but there are endless factors to consider how you are implementing your auth sso solution.
🎯 1
q
Depending on the app, I usually check auth on either the OnRequestStart -or- secured pages (totally depends on the app, if we only have a small secured area, or if it is mostly secured with a few exceptions). Depending on how you are doing the security checks, there may not need to be much of a performance hit. Simply checking a local CFC/class in memory if the user is still logged in shouldn't be too much of a hit. Having to do a deep call into an oAuth provider or GraphAPI call to check if the auth is still good would be a huge hit (but could also be done in the background too)
b
It would be a GraphAPI call each time, but I think it's in the same data center, so there's that.
p
Coldbox and CBSecurity an option??
q
Doing a GraphAPI call over HTTPS will always add about 150-300ms in just transaction time... You may not want to do that on /every/ call.
p
Go JWT, much lighter and wont need to hit DB on every call
b
I probably should know this, but what is JWT? Maybe I should call the work day done. lol
p
JSON Web Token stored client side and verified from page to page of your app; can contain permissions etc and expire after X time or be regularly renewed as user navigates around to keep it alive longer
Its a common auth practice but that link gives good insight related to CF and using it granted that is a Coldbox tool
q
JWTs won't really solve the issue of the auth being pulled out from under them when the user uses SSO to logout in a different app. They still need to check to see if the SSO tokens are still valid on a regular basis.
p
Yes but the request
onRequestStart
is checking a lightweight token for validity or to see if it has been in a revoke list, then it can prevent actions from other actions and force back to auth
q
I could see the need for needing the JWTs if you are going across domains or app servers (or APIs), but if everything is served from a single service/server/app, keeping things locally on the server is much easier and lightweight. You could then check periodically if the auth is still valid on the backend (you'd do this with the app generated JWT anyway).
p
Well he did say SSO, so multiple applications 🤷🏻‍♂️
q
Well, they may just be participating in SSO. I know in my case, my apps hook into our enterprise SSO realm for authentication, but the app itself is self-standing.