DEV Community

#authentication

User authentication mechanisms

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
PKCE Downgrade Attack: When the Authorization Server Accepts Both Flows

PKCE Downgrade Attack: When the Authorization Server Accepts Both Flows

Comments
5 min read
LDAP Injection in API Login Endpoints: Filter Corruption, CVEs, and the Active Directory Scope

LDAP Injection in API Login Endpoints: Filter Corruption, CVEs, and the Active Directory Scope

Comments
5 min read
JWT Vulnerabilities Are API Design Bugs: Three Implementation Decisions That Betray Cryptographic Intent

JWT Vulnerabilities Are API Design Bugs: Three Implementation Decisions That Betray Cryptographic Intent

Comments
5 min read
Type Juggling in API Authentication: How Sending `true` Bypasses a Password Check

Type Juggling in API Authentication: How Sending `true` Bypasses a Password Check

Comments
5 min read
Working: Device Flow Phishing -- The OAuth Attack That Uses the Real Login Page

Working: Device Flow Phishing -- The OAuth Attack That Uses the Real Login Page

Comments
5 min read
SAML XSW: Signatures That Validate the Wrong Element

SAML XSW: Signatures That Validate the Wrong Element

Comments
5 min read
JWT Key Reference Injection: The Attack Class That Wins Bounties While Guides Miss It

JWT Key Reference Injection: The Attack Class That Wins Bounties While Guides Miss It

Comments
5 min read
API Session Fixation Is Three Attacks, Not One — and Rotating Tokens Blocks None of Them

API Session Fixation Is Three Attacks, Not One — and Rotating Tokens Blocks None of Them

Comments
5 min read
Server-Sent Events Security: How EventSource Breaks Your API Authentication Model

Server-Sent Events Security: How EventSource Breaks Your API Authentication Model

Comments
4 min read
Rate Limiting Fails in Production Because It Counts the Wrong Dimension

Rate Limiting Fails in Production Because It Counts the Wrong Dimension

Comments
6 min read
The OAuth Implicit Flow Is Deprecated, But Your Access Tokens Are Still Leaking

The OAuth Implicit Flow Is Deprecated, But Your Access Tokens Are Still Leaking

Comments
4 min read
OAuth Access Token Leakage via Logs and APM: The RFC 6750 Warning Nobody Enforced

OAuth Access Token Leakage via Logs and APM: The RFC 6750 Warning Nobody Enforced

Comments
5 min read
Three Signal Channels Leak Valid Account Lists Before Authentication Completes: Status Code, Response Body, and Timing

Three Signal Channels Leak Valid Account Lists Before Authentication Completes: Status Code, Response Body, and Timing

Comments
5 min read
OAuth 2.0 redirect_uri Bypass: The 5-Condition Matrix That Determines Exploitability

OAuth 2.0 redirect_uri Bypass: The 5-Condition Matrix That Determines Exploitability

Comments
6 min read
AuthGeek: a desktop TOTP authenticator with an Argon2 vault and no cloud sync

AuthGeek: a desktop TOTP authenticator with an Argon2 vault and no cloud sync

Comments
2 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.