Rob Bos · @Rob_Bos
148 followers · 1089 posts · Server mstdn.social

Big step forward in security for Azure DevOps! Skip the service principle and make it a just-in-time connection using OIDC!

Public preview of Workload identity federation for Azure Pipelines - Azure DevOps Blog devblogs.microsoft.com/devops/

#oidc #azuredevops

Last updated 1 year ago

Alexandre Nรฉdรฉlec · @techwatching
21 followers · 63 posts · Server mas.to

Great news for Azure Pipelines ๐Ÿ‘‰devblogs.microsoft.com/devops/

It should not be very different to configure from what I did for provisioning an Azure Ready GitHub Repository ๐Ÿ‘‰ techwatching.dev/posts/azure-r

#oidc #cicd #azuredevops #azure

Last updated 1 year ago

Julian Lam · @devnull
270 followers · 1195 posts · Server crag.social

@deadsuperhero @dansup I could be mistaken, but it really seems like and are very similar... insomuch that when creating a single SSO plugin for one, I also created one for the latter.

#oauth2 #oidc

Last updated 1 year ago

Rachel · @transitory
230 followers · 552 posts · Server hachyderm.io

Lastly the apps of the

* (which is doing quite a bit, worthy of its own topic)
* Nextcloud (did some custom stuff with the deploy)
* Matrix/Element
* Guacamole
* Tandoor (recipe app)
* Jellyfin/Emby + supporting apps
* Adguard-DNS (because the pi-hole container is a mess)
* Unifi Controller
* Cluster Monitoring via Grafana/Prometheus
* Keycloak for for the above apps with support
* Esphome dashboard

Adding cameras soon via frigate

#homelab #homeassistant #oidc #Passkey

Last updated 1 year ago

Farah Juma · @farahjuma
15 followers · 2 posts · Server fosstodon.org

With @wildflyas 29, itโ€™s now possible to secure the WildFly Management Console with using the OIDC Client subsystem. Want to learn more? Check out this blog post:

wildfly-security.github.io/wil

#oidc #elytron

Last updated 1 year ago

Manuel Viens :fediquebec: · @manu
25 followers · 106 posts · Server pouet.fedi.quebec

@firefish Is there a way with to delegate authentication to an like Authentik (goauthentik.io/integrations/se) via , , or similar?

#firefish #sso #oidc #saml #ldap

Last updated 1 year ago

Authgear · @authgear
6 followers · 9 posts · Server oursky.social

๐Ÿ‘‹ In this post, you will learn ๐ก๐จ๐ฐ ๐ญ๐จ ๐š๐๐ ๐š๐ฎ๐ญ๐ก๐ž๐ง๐ญ๐ข๐œ๐š๐ญ๐ข๐จ๐ง ๐ญ๐จ ๐ฒ๐จ๐ฎ๐ซ ๐‰๐š๐ฏ๐š ๐’๐ฉ๐ซ๐ข๐ง๐  ๐๐จ๐จ๐ญ using OAuth2 with Authgear as the Identity Provider (IdP).

authgear.com/post/authenticati

#authentication #java #springboot #oauth2 #openid #oidc

Last updated 1 year ago

Lauritz · @lauritz
75 followers · 24 posts · Server ruhr.social

So, there are formal security considerations on how to implement "OAuth 2.0 for Browser-Based Apps" using Service Workers.

But if you actually decide to go down this rabbit hole, you definitely would want to functional test your solution THOROUGHLY for ALL browsers. ๐Ÿซ 

(4/4)

#oauth #oidc #sso #appsec #webdevelopment

Last updated 1 year ago

Lauritz · @lauritz
75 followers · 20 posts · Server ruhr.social

[Blog Post] Unauthenticated to ATO using Gadget Chain

Just blogged about a vulnerability chain I recently discovered in a private bug bounty program:
security.lauritz-holtmann.de/p

TL;DR: If you encounter an SSO implementation, make sure to test the /callback endpoint for XSS within the OAuth/OIDC "error_description" parameter.

Always try to escalate "non-exploitable" XSS-vulns (Self-XSS, only possible when user has no active session, โ€ฆ) using SSO gadgets.

#xss #sso #bugbounty #vuejs #oidc #oauth

Last updated 1 year ago

Julio Jimenez · @julioj
183 followers · 1825 posts · Server fosstodon.org

Suddenly having issues authenticating your GitHub Workflows to AWS using OIDC? This might be why...

github.blog/changelog/2023-06-

#github #aws #oidc

Last updated 1 year ago

Andrรฉ Koot ๐Ÿง · @meneer
784 followers · 1385 posts · Server mastodon.myfed.space

In Agile n00b world: we need azure devops to develop the AAD sso connection
๐Ÿ˜ตโ€๐Ÿ’ซ

#oidc

Last updated 1 year ago

ciscoffeine · @transcaffeine
661 followers · 23107 posts · Server mond-basis.eu

docs.rs/axum-util/0.1.0/axum_u

i found this in `axum-util` and now i'm wondering how hard it is to use this to secure endpoints with a set of expected claims from a token. are there maybe any examples using axum-util? so far i found crates.io/crates/jwt-authorize which looks good but not sure if it is the right thing.

#rust #oidc

Last updated 1 year ago

Resharing from Nov 2022: I put together a basic proof of concept for using existing installations as SSO for , using . Here's what the authentication and authorization flow for that looks like!

While Mastodon doesn't support , is just on top of .0. If your app allows configuring all URLS for your ldP you can use nearly any OAuth2.0 provider.

Avatars currently aren't supported via this (| added one) but can be!

blimps.xyz/@ceralor/1094004476

#mastodon #matrix #synapse #openldconnect #oidc #OpenlD #oauth2

Last updated 1 year ago

that you donโ€™t need an library like โ€™s fortify. Just host an AuthN provider and implement or .

If you ship a desktop app, you donโ€™t need because the user is authenticated through their login into their computer.

If you ship to a business, they will have an LDAP or OIDC server or will host one when needed.

If you ship an app with online account, you can just host or or pay .

More below:

reddit.com/r/golang/comments/y

#TIL #auth #laravel #oidc #ldap #authn #keycloak #authentic #auth0

Last updated 1 year ago

Ed W8EMV · @w8emv
341 followers · 510 posts · Server hachyderm.io

next up, tailscale login.

Use Google, Microsoft, Github, Apple, Okta, Onelogin, custom

new: passkeys, tied to device or keychain, based on in browser

use "second factor" as primary factor.

demo ensues. "Sign in with passkey". Demo 1 fails. Demo 2 succeeds. Demo 3 uses hardware security key, works the first time.

"If you have enough demos, one of them has to work."

Replace passwords!

[ @tailscale ]

#oidc #webauthn #tailscaleup #Tailscale

Last updated 1 year ago

Alyssa · @alyssa
156 followers · 751 posts · Server cloudisland.nz

Dead SaaS providers:

Please stop making SSO part of your enterprise plans! We're a small group and would love to get started with your free or low cost options but not being able to use our auth system is a _problem_. Security is not an optional extra!

#security #SSO #oauth #oidc

Last updated 1 year ago

New on my YouTube channel: Update Feature | Niko Kรถbler (@dasniko)

youtube.com/watch?v=KmwgQiL6kM

#video #keycloak #email #oidc #authentication

Last updated 1 year ago

New on my YouTube channel: Update Feature | Niko Kรถbler (@dasniko)
youtube.com/watch?v=KmwgQiL6kM

#video #keycloak #email #oidc #authentication

Last updated 1 year ago

Gonรงalo Valรฉrio · @dethos
309 followers · 1321 posts · Server s.ovalerio.net

"From GitHub to Account Takeover: Misconfigured Actions Place GCP & AWS Accounts at Risk "

rezonate.io/blog/github-miscon

#github #oidc #cloud #security

Last updated 1 year ago