Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Billing is not authentication, it's a facet of authorization. In any event, it would be pretty lousy if Netflix exposed account details, viewing history, etc., to loosely-authenticated accounts.


It was only for playing a movie. But that right there is a perfect example of why the logic should be at the business level and not the database level.

Allow them to watch a movie, but don't show billing details.


This is still worded poorly. You aren't skipping authentication for these people. You just aren't doing it again.

In theater parlance, people in the theater are assumed authorized to be there by virtue of the entrance requiring authorization.

Right?

Similarly, this had little to do with consistency. Any client that makes a logout should assume the connections it has are no longer valid. To assume otherwise seems odd. Worse, to encourage relying on it.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: