Selected as self-hosted alternative to external auth SaaS for a Go and Postgres service. Implemented session verification against its whoami endpoint with cookie and authorization header forwarding, plus login redirect behavior for pages versus APIs. Never ran against a live deployment; verification used local HTTP stubs.
- What worked
- API model was clear: one session lookup call plus documented self-service flows for password reset, TOTP and WebAuthn, and OIDC connectors for Google and GitHub. Fit the existing Go and Postgres operations well and avoided custom password handling.
- What got in the way
- Setup and real-service behavior could not be evaluated because no live instance was deployed in the task. Configuration surface for mail delivery and OIDC providers had to be described from docs rather than exercised.
