DEV Community

#authentication

User authentication mechanisms

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Support Account Defense: Balancing JWKS Caching Against Live Session Introspection

Support Account Defense: Balancing JWKS Caching Against Live Session Introspection

Comments
8 min read
OAuth Flow CSRF: How a Missing State Parameter Enables Forced Authorization

OAuth Flow CSRF: How a Missing State Parameter Enables Forced Authorization

Comments
5 min read
HMAC Proves Origin, Not Freshness: Replay Attacks Against Signed APIs

HMAC Proves Origin, Not Freshness: Replay Attacks Against Signed APIs

Comments
6 min read
Working: Magic Link Tokens Live in Your Logs — And TOTP Has a Second Endpoint

Working: Magic Link Tokens Live in Your Logs — And TOTP Has a Second Endpoint

Comments
5 min read
PKCE Downgrade Attack: When the Authorization Server Accepts Both Flows

PKCE Downgrade Attack: When the Authorization Server Accepts Both Flows

Comments
5 min read
SAML XSW: Signatures That Validate the Wrong Element

SAML XSW: Signatures That Validate the Wrong Element

Comments
5 min read
Working: Device Flow Phishing -- The OAuth Attack That Uses the Real Login Page

Working: Device Flow Phishing -- The OAuth Attack That Uses the Real Login Page

Comments
5 min read
Server-Sent Events Security: How EventSource Breaks Your API Authentication Model

Server-Sent Events Security: How EventSource Breaks Your API Authentication Model

Comments
4 min read
JWT Vulnerabilities Are API Design Bugs: Three Implementation Decisions That Betray Cryptographic Intent

JWT Vulnerabilities Are API Design Bugs: Three Implementation Decisions That Betray Cryptographic Intent

Comments
5 min read
Rate Limiting Fails in Production Because It Counts the Wrong Dimension

Rate Limiting Fails in Production Because It Counts the Wrong Dimension

Comments
6 min read
JWT Key Reference Injection: The Attack Class That Wins Bounties While Guides Miss It

JWT Key Reference Injection: The Attack Class That Wins Bounties While Guides Miss It

Comments
5 min read
Type Juggling in API Authentication: How Sending `true` Bypasses a Password Check

Type Juggling in API Authentication: How Sending `true` Bypasses a Password Check

Comments
5 min read
LDAP Injection in API Login Endpoints: Filter Corruption, CVEs, and the Active Directory Scope

LDAP Injection in API Login Endpoints: Filter Corruption, CVEs, and the Active Directory Scope

Comments
5 min read
API Session Fixation Is Three Attacks, Not One — and Rotating Tokens Blocks None of Them

API Session Fixation Is Three Attacks, Not One — and Rotating Tokens Blocks None of Them

Comments
5 min read
The OAuth Implicit Flow Is Deprecated, But Your Access Tokens Are Still Leaking

The OAuth Implicit Flow Is Deprecated, But Your Access Tokens Are Still Leaking

Comments
4 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.