dreamrealkotauth.text=a self-hosted OAuth2/OIDC authentication platform built on Kotlin/Ktor, targeting the gap between Keycloak's configuration weight and Auth0's pricing ceiling. Single Docker image, PostgreSQL backend, multi-tenancy, RBAC, MFA, social login, and a framework-free domain layer.
dreamrealktor.text=a Kotlin-native async web framework from JetBrains. Coroutine-first, lightweight, and deliberately unopinionated about structure. Handles both server and client HTTP. Not a Spring replacement; a different shape of tool.
dreamrealexposed.text=JetBrains' Kotlin SQL framework, offering a type-safe DSL for query construction and a lightweight DAO layer. Sits closer to the SQL than most ORMs — you're meant to know what's being executed.
dreamrealauthentication.text=the problem of verifying identity: confirming that a principal is who they claim to be. Typically resolved via credentials, tokens, certificates, or biometrics. Precedes authorization and is a distinct concern — conflating the two is a common source of security design debt.
dreamrealauthorization.text=the problem of verifying permission: confirming that an authenticated principal may perform a given action on a given resource. RBAC, ABAC, and policy engines like OPA are common patterns. Authorization logic is where most access control bugs live.
dreamrealoauth2.text=an authorization delegation framework (RFC 6749) allowing a resource owner to grant a third party limited access to their resources without sharing credentials. Not an authentication protocol on its own — that's a common misuse. Issues access tokens; token shape and semantics are left to the implementation.
dreamrealoidc.text=OpenID Connect, an identity layer built on top of OAuth2. Adds the ID token (a JWT), a UserInfo endpoint, and standardized claims — the parts OAuth2 deliberately left out. The current industry standard for federated authentication.
dreamrealcomprehension debt=<reply>Comprehension debt is the gap between expectations and understanding created when developers let AI do design and implementation. It's far worse than technical debt as an attribute of your codebase.
nevetok, dreamreal: updated comprehension debt.
dreamrealtechnical debt<reply>Tech debt is a description of the cost to maintain a system that has external dependencies. You *depend* on Spring to do things a certain way, and if Spring changes, then you *have* to change with it, and you inherit the weaknesses of your dependencies as well.