why don't more sites do it like this? i think because
- wow oauth and oidc are tedious
- google and facebook and apple and microsoft and auth0 by okta would all prefer that you use code that they control, or pay for their service instead of rolling your own
- why would you go to the effort to avoid storing session data on your server when you have this huge database right here to collect as much customer info as possible to sell to the highest bidder
what other clever hacks could i do with a lil lua plugin to haproxy!







)