DEV Community

#authentication

User authentication mechanisms

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
What are JWT tokens and why your app needs them

What are JWT tokens and why your app needs them

1
Comments
4 min read
Node.js SMS OTP Login Without Webhooks: Polling, Retry, Resend, and Abuse Prevention

Node.js SMS OTP Login Without Webhooks: Polling, Retry, Resend, and Abuse Prevention

Comments
7 min read
Server-Sent Events Security: How EventSource Breaks Your API Authentication Model

Server-Sent Events Security: How EventSource Breaks Your API Authentication Model

Comments
4 min read
SAML XSW: Signatures That Validate the Wrong Element

SAML XSW: Signatures That Validate the Wrong Element

Comments
5 min read
HMAC Proves Origin, Not Freshness: Replay Attacks Against Signed APIs

HMAC Proves Origin, Not Freshness: Replay Attacks Against Signed APIs

Comments
6 min read
OAuth Flow CSRF: How a Missing State Parameter Enables Forced Authorization

OAuth Flow CSRF: How a Missing State Parameter Enables Forced Authorization

Comments
5 min read
OAuth Access Token Leakage via Logs and APM: The RFC 6750 Warning Nobody Enforced

OAuth Access Token Leakage via Logs and APM: The RFC 6750 Warning Nobody Enforced

Comments
5 min read
PKCE Downgrade Attack: When the Authorization Server Accepts Both Flows

PKCE Downgrade Attack: When the Authorization Server Accepts Both Flows

Comments
5 min read
Working: Magic Link Tokens Live in Your Logs — And TOTP Has a Second Endpoint

Working: Magic Link Tokens Live in Your Logs — And TOTP Has a Second Endpoint

Comments
5 min read
Rate Limiting Fails in Production Because It Counts the Wrong Dimension

Rate Limiting Fails in Production Because It Counts the Wrong Dimension

Comments
6 min read
Type Juggling in API Authentication: How Sending `true` Bypasses a Password Check

Type Juggling in API Authentication: How Sending `true` Bypasses a Password Check

Comments
5 min read
JWT Key Reference Injection: The Attack Class That Wins Bounties While Guides Miss It

JWT Key Reference Injection: The Attack Class That Wins Bounties While Guides Miss It

Comments
5 min read
Working: Device Flow Phishing -- The OAuth Attack That Uses the Real Login Page

Working: Device Flow Phishing -- The OAuth Attack That Uses the Real Login Page

Comments
5 min read
LDAP Injection in API Login Endpoints: Filter Corruption, CVEs, and the Active Directory Scope

LDAP Injection in API Login Endpoints: Filter Corruption, CVEs, and the Active Directory Scope

Comments
5 min read
API Session Fixation Is Three Attacks, Not One — and Rotating Tokens Blocks None of Them

API Session Fixation Is Three Attacks, Not One — and Rotating Tokens Blocks None of Them

Comments
5 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.