tbroyer, to Java
@tbroyer@piaille.fr avatar

connect2id's Nimbus OAuth2/OIDC SDK is underrated, particularly as a direct dependency!

https://connect2id.com/products/nimbus-oauth-openid-connect-sdk

Many people use it through Spring Security or Pac4j but the lib is relatively easy to use directly (particularly if you know the protocols) and can be used to add OIDC support to Java apps with much less complexity than those Spring or Pac4j authentication frameworks (but at the cost of having to handle some of the Web security yourself, mainly around CSRF)

preslavrachev, to random
@preslavrachev@mastodon.social avatar

Every time I get to set up on a new app, I am mentally preparing for a 3-day marathon of reading some half-useful docs and tweaking options until it clicks.

I get it, software security is hard (and rightfully so), but this is just nuts.

freiefunken, to linux German
@freiefunken@mastodon.social avatar

Wer mag, kann bei den Chemnitzer Linuxtagen was über Single Sign-on für Webanwendungen von mir hören. Ist aber für die, die sonntags morgens nicht verschlafen. 😉

https://chemnitzer.linux-tage.de/2024/de/programm/beitrag/213

matrix, to Matrix
@matrix@mastodon.matrix.org avatar

Blazing fast Matrix, Native E2EE Group Calls, state of the art auth and potential WhatsApp interop.

Matthew covers the last year in Matrix and how it can be used to speed up the opening of communications silo required by the EU Digital Markets Act

https://youtu.be/s5BrVVf0B1I

cooptilleuls, to random French
@cooptilleuls@mastodon.online avatar

[Best of] Découvrez dans cet article de @vincentchalamon le protocole OpenID Connect () et comment configurer @ApiPlatform avec. Bonus : cet article est aussi une conférence de l' 2023, disponible en replay 😉 https://les-tilleuls.coop/blog/un-pas-vers-la-decentralisation-reprenons-le-controle-grace-a-oidc

miketheman, to python
@miketheman@hachyderm.io avatar

Thanks @github for the docs update!
New page on how to enable trusted publishing to @pypi

https://docs.github.com/en/actions/deployment/security-hardening-your-deployments/configuring-openid-connect-in-pypi

More detailed (with pictures 🖼️ ) authored by @yossarian and other contributors!
https://docs.pypi.org/trusted-publishers/

lemonldapng, to opensource

🌟 This is the official Mastodon account for LemonLDAP::NG, a Web Single Sign On free software compatible with many open standards like CAS, SAML and OpenID Connect.

ℹ️ We will publish here information about releases and new features. Please follow us!

🌐 See also our official website: https://www.lemonldap-ng.org

farahjuma, to random

With @wildflyas 29, it’s now possible to secure the WildFly Management Console with using the OIDC Client subsystem. Want to learn more? Check out this blog post:

https://wildfly-security.github.io/wildfly-elytron/blog/securing-management-console-oidc/

pixelfed, to Pixelfed
@pixelfed@mastodon.social avatar

We are working on OIDC support, and exploring IndieAuth!

The Sign-in with Mastodon feature uses Mastodon specific APIs and is a temporary measure until we get OIDC in place and other platforms support it!

bruienne, to random

And so the rollout of new documentation and announcements begins:

"What’s new in Apple platform deployment”

https://support.apple.com/guide/deployment/whats-new-dep950aed53e/1/web/1.0

Security-related highlights: iCloud Keychain for Managed Apple ID and Passkeys at work! Also: custom IdPs for federation: OIDC, SCIM and Shared Signals (https://sharedsignals.guide)! New Platform SSO features as well! Managed Device Attestation for macOS! Watch for sessions later this week for more info.

image/png
image/png
image/png

blake, to random

I just hooked up source.blakes.dev to (exclusively) sign in with . All it took was setting it up in /admin/auths and in Keycloak and adding a redirect to Traefik according to this comment: https://github.com/go-gitea/gitea/issues/13606#issuecomment-1421630270

kris, to random
@kris@outmo.de avatar

Very exited for user self-registration coming to the Canaille frontend: https://gitlab.com/yaal/canaille/-/issues/55#note_1381533038

Basically this makes it the perfect solution for small to medium sized SSO for public services.

Time to get it working with LLDAP https://github.com/lldap/lldap/ :ablobcatbongo:

miketheman, to programming
@miketheman@hachyderm.io avatar

Live launch from the floor of @PyConUS

Starting today, PyPI package maintainers can adopt a new, more secure publishing method that does not require long-lived passwords or API tokens to be shared with external systems.

https://blog.pypi.org/posts/2023-04-20-introducing-trusted-publishers/

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • kavyap
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • tacticalgear
  • cubers
  • Youngstown
  • mdbf
  • slotface
  • rosin
  • osvaldo12
  • ngwrru68w68
  • GTA5RPClips
  • provamag3
  • InstantRegret
  • everett
  • Durango
  • cisconetworking
  • khanakhh
  • ethstaker
  • tester
  • anitta
  • Leos
  • normalnudes
  • modclub
  • megavids
  • lostlight
  • All magazines