#auth — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #auth, aggregated by home.social.
-
Implement BFF using Auth0, Angular and #ASPNETCore
https://damienbod.com/2026/08/10/implement-bff-using-auth0-angular-and-asp-net-core/
#dotnet #webdev #angular #auth #auth0 #bff #patterns #csharp
-
Implement BFF using Auth0, Angular and #ASPNETCore
https://damienbod.com/2026/08/10/implement-bff-using-auth0-angular-and-asp-net-core/
#dotnet #webdev #angular #auth #auth0 #bff #patterns #csharp
-
📢 New #updates · 10 Aug #9
· MeiliSearch v1.53.0 — Foreign filters now shard and retrieve more documents
· oceanbase v5.0.1_CE
· lightdash 1.108.0 — Fixed live data queries and download URL signing
· WriteFreely v0.17.2 — OAuth adapter improved, fixed collection rendering, invite validation addedBrowse everything at https://selfhost.directory
-
📢 New #updates · 10 Aug #9
· MeiliSearch v1.53.0 — Foreign filters now shard and retrieve more documents
· oceanbase v5.0.1_CE
· lightdash 1.108.0 — Fixed live data queries and download URL signing
· WriteFreely v0.17.2 — OAuth adapter improved, fixed collection rendering, invite validation addedBrowse everything at https://selfhost.directory
-
📢 New #updates · 10 Aug #2.1
· DockSTARTer v1.20260809.1 — Improved logging for uninstall command
Check out more on https://selfhost.directory
-
📢 New #updates · 10 Aug #2.1
· DockSTARTer v1.20260809.1 — Improved logging for uninstall command
Check out more on https://selfhost.directory
-
Kunden-Anfrage kurz vorm Wochenende: wo denn 2FA für das IMAP/SMTP-Postfach eingerichtet werden kann.
Sehr gute Motivation. Da reicht es aber nicht, das RoundCube-Plugin dafür zu aktivieren.
... das wird also ein richtiger Spaß.
Sind IMAP/SMTP "durch"? 2FA können wir damit meines Erachtens doch nicht realisieren.
Oder bleibt nur noch JMAP, eine eigene App, und/oder OAuth-APIs?
#2fa #auth -
Kunden-Anfrage kurz vorm Wochenende: wo denn 2FA für das IMAP/SMTP-Postfach eingerichtet werden kann.
Sehr gute Motivation. Da reicht es aber nicht, das RoundCube-Plugin dafür zu aktivieren.
... das wird also ein richtiger Spaß.
Sind IMAP/SMTP "durch"? 2FA können wir damit meines Erachtens doch nicht realisieren.
Oder bleibt nur noch JMAP, eine eigene App, und/oder OAuth-APIs?
#2fa #auth -
📢 New #updates · 6 Aug #1
· windmill v1.781.0 — Enhanced tree view pager and workspace nesting capabilities
· arize-phoenix arize-phoenix-v19.18.0 — Added REST endpoint and expression filter DSL for sessions
· Arcane v2.7.0
· PowerDNS-Admin v0.6.0 — Fixed URL encoding, synced zone catalog, resolved auth errorCheck out more on https://selfhost.directory
-
📢 New #updates · 6 Aug #1
· windmill v1.781.0 — Enhanced tree view pager and workspace nesting capabilities
· arize-phoenix arize-phoenix-v19.18.0 — Added REST endpoint and expression filter DSL for sessions
· Arcane v2.7.0
· PowerDNS-Admin v0.6.0 — Fixed URL encoding, synced zone catalog, resolved auth errorCheck out more on https://selfhost.directory
-
Modern authentication in #ASPNETCore with 2FA and passkey
https://blog.elmah.io/modern-authentication-in-asp-net-ore-with-2fa-and-passkey/
-
Modern authentication in #ASPNETCore with 2FA and passkey
https://blog.elmah.io/modern-authentication-in-asp-net-ore-with-2fa-and-passkey/
-
📢 New #updates · 4 Aug #7.1
· rudderstack v1.82.0 — Enhanced destination processing and transformer-proxy contract breach detection
Full changelogs → https://selfhost.directory
-
📢 New #updates · 4 Aug #7.1
· rudderstack v1.82.0 — Enhanced destination processing and transformer-proxy contract breach detection
Full changelogs → https://selfhost.directory
-
📢 New #updates · 3 Aug #11
· Wekan v10.57 — Fixed SSRF vulnerabilities with redirect handling in imports
· lightdash 1.65.0 — Charts now link to their source data app viz
· Tolgee v3.216.0 — Added Google Workspace as SSO provider optionAll updates live on https://selfhost.directory
-
📢 New #updates · 3 Aug #11
· Wekan v10.57 — Fixed SSRF vulnerabilities with redirect handling in imports
· lightdash 1.65.0 — Charts now link to their source data app viz
· Tolgee v3.216.0 — Added Google Workspace as SSO provider optionAll updates live on https://selfhost.directory
-
📢 New #updates · 2 Aug #3
· Wekan v10.56 — Added Node.js support for i386, armhf, and loong64 architectures
· suna v0.12.0 — Centralized audit logs, session cost tracking, enhanced session controls
· lightdash 1.59.0 — Redesigned pre-auth screens and fixed SSO method recordingAll updates live on https://selfhost.directory
-
📢 New #updates · 2 Aug #3
· Wekan v10.56 — Added Node.js support for i386, armhf, and loong64 architectures
· suna v0.12.0 — Centralized audit logs, session cost tracking, enhanced session controls
· lightdash 1.59.0 — Redesigned pre-auth screens and fixed SSO method recordingAll updates live on https://selfhost.directory
-
If a (web) app really needs a login, which one would you feel most comfortable using?
-
If a (web) app really needs a login, which one would you feel most comfortable using?
-
Чек‑лист внедрения аутентификации Manticore в продакшн
В проде подход «включил и готово» почти никогда не работает. Для автономного узла техническая последовательность короткая: включить auth , перезапустить Manticore, создать администратора и обновить клиентов. В топологии с распределёнными таблицами или репликационными кластерами нужна дополнительная подготовка, потому что узлам тоже приходится аутентифицироваться друг у друга. Относитесь к внедрению как к небольшому релизу. Сначала инвентаризируйте клиентов и узлы, подготовьте данные аутентификации и отрепетируйте процедуру для своей топологии. Затем переключайтесь. Репетиция выявит сбои до технологического окна. Этот чек‑лист написан для пользователей, которые планируют включить аутентификацию и хотят сделать это максимально безопасно для текущей системы. Помните, что аутентификация отключена, пока вы не настроите auth ; после переключения клиенты, которые по‑прежнему не передают учётные данные будут получать отказ. Выберите процедуру по топологии:
https://habr.com/ru/articles/1064226/
#auth #authentication #authorization #аутентификация #авторизация #информационная_безопасность #production #продакшн #продакшен
-
Как защитить Manticore Search с помощью встроенной аутентификации и авторизации
Поиск нередко считают просто инфраструктурой. Но в продакшене он фактически работает как API приложения: принимает пользовательский трафик, отдаёт бизнес‑данные, обслуживает дашборды и нередко стоит рядом с записями, которые не должны быть доступны каждому клиенту в сети. В Manticore Search теперь (с релиза 27.1.5 ) есть встроенная аутентификация и авторизация — для SQL по протоколу MySQL, для HTTP/HTTPS‑эндпоинтов и для операций, связанных с репликацией. Аутентификация отвечает на вопрос «кто делает запрос?». Авторизация — «что этому пользователю разрешено делать?». Пользователи, которые уже используют Manticore могут подключить новую функциональность, сохранив привычные способы работы с Manticore. Существующие SQL и HTTP‑клиенты сохраняют свои обычные паттерны подключения. В приложениях требуются минимальные изменения.
https://habr.com/ru/articles/1063744/
#аутентификация #авторизация #mysql #sql #логирование #управление_правами_доступа #защищенный_режим #auth #authentication #authorization
-
[Перевод] Книга аутентификации
Это моя личная книга по аутентификации. Она представляет собой сборник руководств, рекомендаций и примеров по внедрению аутентификации в веб-приложениях, основанный на моем личном опыте. Книга совершенно бесплатна и не содержит рекламы. Надеюсь, она будет полезна всем, кто хочет узнать больше об аутентификации, безопасности и веб-технологиях в целом. Как следует из названия, эта книга в значительной степени посвящена системе аутентификации и авторизации для веб-приложений. Более общие вопросы безопасности см. в серии “Шпаргалки OWASP” . Если у вас возникнут какие-либо вопросы, не стесняйтесь задавать их на сервере Discord или в обсуждениях на GitHub . Разработано и поддерживается Pilcrow . Исходный код доступен на GitHub .
https://habr.com/ru/articles/1063760/
#javascript #js #go #golang #auth #authentication #authorization #passkey #basic_auth #аутентификация
-
📢 New #updates · 27 Jul #2.1
· silex v3.9.0 — Improved data source panels and added text selection styling
· DockSTARTer v1.20260726.1 — Fixed log file truncation causing occasional panicsMore self-hosted updates → https://selfhost.directory
-
📢 New #updates · 27 Jul #2.1
· silex v3.9.0 — Improved data source panels and added text selection styling
· DockSTARTer v1.20260726.1 — Fixed log file truncation causing occasional panicsMore self-hosted updates → https://selfhost.directory
-
📢 New #updates · 25 Jul #1
· Sunshine v2026.724.182739 — Fixed macOS scroll speed and updated dependencies
· Wekan v10.36 — Fixed invalid HTML in avatar selection and deletion links
· convex precompiled-2026-07-24-041376c — Enhanced dashboard security with password and MFA management
· fluxer 2026.724.211948 — Updated media proxy imageCheck out more on https://selfhost.directory
-
📢 New #updates · 25 Jul #1
· Sunshine v2026.724.182739 — Fixed macOS scroll speed and updated dependencies
· Wekan v10.36 — Fixed invalid HTML in avatar selection and deletion links
· convex precompiled-2026-07-24-041376c — Enhanced dashboard security with password and MFA management
· fluxer 2026.724.211948 — Updated media proxy imageCheck out more on https://selfhost.directory
-
📢 New #updates · 24 Jul #2
· convex precompiled-2026-07-23-19431ea — Added MFA for profile and primary email changes
· webstudio 0.282.0 — Faster previews, removed TIFF support, improved asset handling
· draw.io v31.0.2
· Ever Gauzy v111.6.0 — Added health endpoint, fixed session middleware bypass
· sablier v1.16.0 — Enhanced Kubernetes support and fixed API context issueCheck out more on https://selfhost.directory
-
Whoever thought this is safe in deepfakes age? All those TikTok training data and a virtual camera, MY LaWd!
-
Whoever thought this is safe in deepfakes age? All those TikTok training data and a virtual camera, MY LaWd!
-
📢 New #updates · 22 Jul #16
· convex precompiled-2026-07-22-024036e — Enhanced list_active_syncs documentation clarity and detail
· lightdash 0.3457.2 — Fixed BigQuery auth, chart access, and day-0 get-started issues
· Olares 1.12.7-20260722Full changelogs → https://selfhost.directory
-
📢 New #updates · 21 Jul #1
· ESPHome 2026.7.1 — Fixed temperature reporting and improved sensor communication
· arize-phoenix arize-phoenix-v19.3.0 — Enhanced auth, playground filtering, and settings documentation added
· lightdash 0.3428.0 — Enhanced analytics for user onboarding and query trackingBrowse everything at https://selfhost.directory
-
📢 New #updates · 21 Jul #1
· ESPHome 2026.7.1 — Fixed temperature reporting and improved sensor communication
· arize-phoenix arize-phoenix-v19.3.0 — Enhanced auth, playground filtering, and settings documentation added
· lightdash 0.3428.0 — Enhanced analytics for user onboarding and query trackingBrowse everything at https://selfhost.directory
-
📢 New #updates · 20 Jul #5.1
· lightdash 0.3420.0 — Enhanced onboarding project wizard with added analytics features
· Ever Gauzy v111.5.0 — Improved activity tracking with new indexes and bug fixes
· dbhub v0.24.0 — TiDB support added and various MySQL/MariaDB fixes implementedAll updates live on https://selfhost.directory
-
📢 New #updates · 19 Jul #12
· Locust 2.46.0 — Fixed integer rounding and improved type hinting
· minecraft 2026.7.1 — Improved networking tools and CurseForge API integration
· lightdash 0.3417.2 — Fixed Google session switching and OAuth grant decoupling
· twill-cms 3.6.0 — Added Laravel 13 support and fixed bugs
· Bambuddy v1.2.5b2-daily.20260719Browse everything at https://selfhost.directory
-
📢 New #updates · 19 Jul #12
· Locust 2.46.0 — Fixed integer rounding and improved type hinting
· minecraft 2026.7.1 — Improved networking tools and CurseForge API integration
· lightdash 0.3417.2 — Fixed Google session switching and OAuth grant decoupling
· twill-cms 3.6.0 — Added Laravel 13 support and fixed bugs
· Bambuddy v1.2.5b2-daily.20260719Browse everything at https://selfhost.directory
-
🚀 New #release · Gotify v3.0.0
Notable features:
• Add OIDC login support. See OIDC Docs (#433 via #941, #977, #982, #1003)
• Thanks to @KovachVL and @alanturing881 for reporting security issues for this feature.
• Add session elevation for sensitive actions in the web UI. Session Elevation Docs (GHSA-3hcj-9m7p-wwm9, #944 via #952, #954).
•…Details, install & alternatives → https://selfhost.directory/project/gotify#update-5674958
-
🚀 New #release · Gotify v3.0.0
Notable features:
• Add OIDC login support. See OIDC Docs (#433 via #941, #977, #982, #1003)
• Thanks to @KovachVL and @alanturing881 for reporting security issues for this feature.
• Add session elevation for sensitive actions in the web UI. Session Elevation Docs (GHSA-3hcj-9m7p-wwm9, #944 via #952, #954).
•…Details, install & alternatives → https://selfhost.directory/project/gotify#update-5674958
-
📢 New #updates · 17 Jul #11.1
· lightdash 0.3408.0 — Added "Revert to published" button for draft edits
· TrailBase v0.31.0 — Batch API overhauled, now returns individual operation results
· Gladys v4.83.0 — Improved sorting and scrolling, fixed MQTT device list spacingAll updates live on https://selfhost.directory
-
📢 New #updates · 17 Jul #11.1
· lightdash 0.3408.0 — Added "Revert to published" button for draft edits
· TrailBase v0.31.0 — Batch API overhauled, now returns individual operation results
· Gladys v4.83.0 — Improved sorting and scrolling, fixed MQTT device list spacingAll updates live on https://selfhost.directory
-
📢 New #updates · 17 Jul #9.1
· kite v0.14.0 — Legacy container image and Helm chart repository deprecated
Check out more on https://selfhost.directory
-
📢 New #updates · 17 Jul #9.1
· kite v0.14.0 — Legacy container image and Helm chart repository deprecated
Check out more on https://selfhost.directory
-
📢 New #updates · 17 Jul #8.1
· mirrord 3.234.0 — Enhanced preview environments with idle mode and connection handling
· mike v0.3.0 — Courtlistener integration, MFA, UI updates and refactoringCheck out more on https://selfhost.directory
-
Let's try this: Anyone interested in #hiring me?
PT Canada
Experience:
- #SupportEngineer #CustomerSupport #SaaS #DevOps
- expert: #Auth #CI integrations #web
- Product #Operations
- Program Management
- #librarianExcel at:
- global collaboration
- #techSupport
- workflows (automation/AI)
- training/mentoring
- #Documentation #knowledgeBase
- troubleshooting
- detail-oriented
- learning
- recognizing patterns & fixingLinks in profile
Boosts appreciated
-
Let's try this: Anyone interested in #hiring me?
PT Canada
Experience:
- #SupportEngineer #CustomerSupport #SaaS #DevOps
- expert: #Auth #CI integrations #web
- Product #Operations
- Program Management
- #librarianExcel at:
- global collaboration
- #techSupport
- workflows (automation/AI)
- training/mentoring
- #Documentation #knowledgeBase
- troubleshooting
- detail-oriented
- learning
- recognizing patterns & fixingLinks in profile
Boosts appreciated
-
Building A Wireless Fingerprint Authorization Device
-
Building A Wireless Fingerprint Authorization Device
-
Manticore Search 27.1.5: Auth, sharding, conversational and faster vector search
https://manticoresearch.com/blog/manticore-search-27-1-5/
#HackerNews #ManticoreSearch #VectorSearch #Auth #Sharding #TechUpdate
-
Manticore Search 27.1.5: Auth, sharding, conversational and faster vector search
https://manticoresearch.com/blog/manticore-search-27-1-5/
#HackerNews #ManticoreSearch #VectorSearch #Auth #Sharding #TechUpdate
-
BadHost – CVE-2026-48710: Starlette Host-Header Auth Bypass
#HackerNews #BadHost #CVE-2026-48710 #Starlette #Security #Vulnerability #Auth #Bypass
-
BadHost – CVE-2026-48710: Starlette Host-Header Auth Bypass
#HackerNews #BadHost #CVE-2026-48710 #Starlette #Security #Vulnerability #Auth #Bypass
-
Achievement unlocked: SSO for the hypervisor! 🎉
My Proxmox VE is now officially using Keycloak OIDC for authentication, and the setup is fantastic:
- Centralized Users: Managed alongside my other apps (Keycloak using my LDAP as the backend).
- Hardware MFA: Locked down with a FIDO2 stick from @nitrokey
- Unified Control: Centralized policies, logging, and RBAC across the board.
Another great improvement for my HomeLab/SelfHosting setup.
#Proxmox #Keycloak #DevOps #Auth #OpenID #Homelab #SelfHosted
-
Achievement unlocked: SSO for the hypervisor! 🎉
My Proxmox VE is now officially using Keycloak OIDC for authentication, and the setup is fantastic:
- Centralized Users: Managed alongside my other apps (Keycloak using my LDAP as the backend).
- Hardware MFA: Locked down with a FIDO2 stick from @nitrokey
- Unified Control: Centralized policies, logging, and RBAC across the board.
Another great improvement for my HomeLab/SelfHosting setup.
#Proxmox #Keycloak #DevOps #Auth #OpenID #Homelab #SelfHosted
-
Interesting take on JWT. Does an SPA really needs it? #web #security #auth https://www.dusanmalusev.dev/blog/jwt-is-a-scam-and-your-app-doesnt-need-it
-
Interesting take on JWT. Does an SPA really needs it? #web #security #auth https://www.dusanmalusev.dev/blog/jwt-is-a-scam-and-your-app-doesnt-need-it