IMHO not rolling your own auth is asking for stuff like this to happen.
This is a terrible take, and to anyone reading this please don't roll your own auth, you will regret it.
There are lots of good options out there that enterprisey abominations.
This is a terrible suggestion. Rolling your own auth nowadays is like rolling your own encryption. It’s just a bad idea. OAuth and OIDC are massive specs that are constantly changing and you’re going to be stuck chasing and developing auth instead of your actual product.
I know because this is what my brain dead principal engineer did and I’ve spent the last 3 years chasing RFCs and am now going to spend the next year migrating to Keycloak because I’ve finally convinced my boss that we’re not an auth company.
I believe the opposite of this statement to be true