home.social

#authorization — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #authorization, aggregated by home.social.

fetched live
  1. US appeals #court blocks #Trump’s $400 million White House #ballroom project

    The Washington-based #US Court of Appeals for the DC Circuit in a divided 2-1 order upheld a preliminary injunction won by the National Trust for #HistoricPreservation, which sued last year after the admin tore down ​the #EastWing & began building a 90,000-square-foot (8,360-square-meter) ballroom both without seeking #authorization from #Congress.

    #law #architecture #landmark #conservation
    reuters.com/world/us-appeals-c

  2. US appeals #court blocks #Trump’s $400 million White House #ballroom project

    The Washington-based #US Court of Appeals for the DC Circuit in a divided 2-1 order upheld a preliminary injunction won by the National Trust for #HistoricPreservation, which sued last year after the admin tore down ​the #EastWing & began building a 90,000-square-foot (8,360-square-meter) ballroom both without seeking #authorization from #Congress.

    #law #architecture #landmark #conservation
    reuters.com/world/us-appeals-c

  3. 5,500 access requests daily. 10,000 employees.

    To scale Just-In-Time Access (JITA), HubSpot redesigned its authorization system with a rule engine architecture.

    Access requests are evaluated through independent rules organized as a directed acyclic graph (DAG), adding structured decision metadata, rule-level observability, and governance workflows.

    Learn how the architecture improves authorization at scale: bit.ly/4fS7EbI

    #SoftwareArchitecture #Authorization #Observability #Security #InfoQ

  4. 5,500 access requests daily. 10,000 employees.

    To scale Just-In-Time Access (JITA), HubSpot redesigned its authorization system with a rule engine architecture.

    Access requests are evaluated through independent rules organized as a directed acyclic graph (DAG), adding structured decision metadata, rule-level observability, and governance workflows.

    Learn how the architecture improves authorization at scale: bit.ly/4fS7EbI

  5. Чек‑лист внедрения аутентификации Manticore в продакшн

    В проде подход «включил и готово» почти никогда не работает. Для автономного узла техническая последовательность короткая: включить auth , перезапустить Manticore, создать администратора и обновить клиентов. В топологии с распределёнными таблицами или репликационными кластерами нужна дополнительная подготовка, потому что узлам тоже приходится аутентифицироваться друг у друга. Относитесь к внедрению как к небольшому релизу. Сначала инвентаризируйте клиентов и узлы, подготовьте данные аутентификации и отрепетируйте процедуру для своей топологии. Затем переключайтесь. Репетиция выявит сбои до технологического окна. Этот чек‑лист написан для пользователей, которые планируют включить аутентификацию и хотят сделать это максимально безопасно для текущей системы. Помните, что аутентификация отключена, пока вы не настроите auth ; после переключения клиенты, которые по‑прежнему не передают учётные данные будут получать отказ. Выберите процедуру по топологии:

    habr.com/ru/articles/1064226/

    #auth #authentication #authorization #аутентификация #авторизация #информационная_безопасность #production #продакшн #продакшен

  6. Как защитить Manticore Search с помощью встроенной аутентификации и авторизации

    Поиск нередко считают просто инфраструктурой. Но в продакшене он фактически работает как API приложения: принимает пользовательский трафик, отдаёт бизнес‑данные, обслуживает дашборды и нередко стоит рядом с записями, которые не должны быть доступны каждому клиенту в сети. В Manticore Search теперь (с релиза 27.1.5 ) есть встроенная аутентификация и авторизация — для SQL по протоколу MySQL, для HTTP/HTTPS‑эндпоинтов и для операций, связанных с репликацией. Аутентификация отвечает на вопрос «кто делает запрос?». Авторизация — «что этому пользователю разрешено делать?». Пользователи, которые уже используют Manticore могут подключить новую функциональность, сохранив привычные способы работы с Manticore. Существующие SQL и HTTP‑клиенты сохраняют свои обычные паттерны подключения. В приложениях требуются минимальные изменения.

    habr.com/ru/articles/1063744/

    #аутентификация #авторизация #mysql #sql #логирование #управление_правами_доступа #защищенный_режим #auth #authentication #authorization

  7. [Перевод] Книга аутентификации

    Это моя личная книга по аутентификации. Она представляет собой сборник руководств, рекомендаций и примеров по внедрению аутентификации в веб-приложениях, основанный на моем личном опыте. Книга совершенно бесплатна и не содержит рекламы. Надеюсь, она будет полезна всем, кто хочет узнать больше об аутентификации, безопасности и веб-технологиях в целом. Как следует из названия, эта книга в значительной степени посвящена системе аутентификации и авторизации для веб-приложений. Более общие вопросы безопасности см. в серии “Шпаргалки OWASP” . Если у вас возникнут какие-либо вопросы, не стесняйтесь задавать их на сервере Discord или в обсуждениях на GitHub . Разработано и поддерживается Pilcrow . Исходный код доступен на GitHub .

    habr.com/ru/articles/1063760/

    #javascript #js #go #golang #auth #authentication #authorization #passkey #basic_auth #аутентификация

  8. Will #AI fix prior #authorization —or make it worse?

    If you’re like me, you or a loved one has struggled through the process of gaining pre-approval for the #medical care that your #physician has recommended. Personal stories abound regarding the tribulations of #patients as they go through hoops to get their #health #insurer to pay for certain #prescription #medications , medical procedures, and more.

    arstechnica.com/ai/2026/07/wil

  9. Will #AI fix prior #authorization —or make it worse?

    If you’re like me, you or a loved one has struggled through the process of gaining pre-approval for the #medical care that your #physician has recommended. Personal stories abound regarding the tribulations of #patients as they go through hoops to get their #health #insurer to pay for certain #prescription #medications , medical procedures, and more.

    arstechnica.com/ai/2026/07/wil

  10. MCP tool authorization should not depend on the model following an instruction.

    This builds a Quarkus MCP server where OPA evaluates skill manifests and caller context — trust tier, signature status, team, scopes — before a tool appears in tools/list or executes.

    Rego compiles to Wasm and evaluates in-process. No sidecar, no network call. Each decision logs a policy version and reason codes.

    the-main-thread.com/p/opa-quar

    #OPA #Quarkus #MCP #Java #Authorization

  11. MCP tool authorization should not depend on the model following an instruction.

    This builds a Quarkus MCP server where OPA evaluates skill manifests and caller context — trust tier, signature status, team, scopes — before a tool appears in tools/list or executes.

    Rego compiles to Wasm and evaluates in-process. No sidecar, no network call. Each decision logs a policy version and reason codes.

    the-main-thread.com/p/opa-quar

    #OPA #Quarkus #MCP #Java #Authorization

  12. Как мы делаем разграничение доступа в одной платформе Сбера

    Наша команда создаёт сервис управления доступом (коротко - СУД) в одной из самых больших в Сбере платформ - Платформе Кибербезопасности, или просто ПКБ. На ней обрабатываются все данные Банка, связанные с кибербезопасностью, а также работает множество продуктов и сервисов, предназначенных для противодействия внутреннему и внешнему мошенничеству, защиты инфраструктуры, а также для мониторинга и анализа различных угроз. Подробнее о том, что собой представляет ПКБ, можно посмотреть в Кибрарии Сбера в статье Аналитическая платформа кибербезопасности. Опыт Сбера . Там же можно узнать, как наш сервис вписан в платформу. В вводной части немного расскажу об архитектуре сервиса, его задачах, с чем мы уже справились и что ещё предстоит сделать и почему. Наш сервис используется в большой гетерогенной среде, которая содержит не только разрабатываемое в банке программное обеспечение, но и opensource-продукты, предоставляющие различную функциональность (Apache Flink и MLFlow), а также управляющие данными (Apache Hadoop, Ozone и Clickhouse).

    habr.com/ru/companies/sberbank

    #доступ #разграничение_доступа #authorization #authz #управление_доступом #авторизация #модель_доступа #ролевая_модель #привилегия #права_доступа

  13. SecretAuth – UX-решение для авторизации посредством приватного ключа

    Мир сильно изменился с начала 21 века. В том числе, что касается систем авторизации. Мы продвинулись от авторизации через обычный логин и пароль к использованию централизованных сервисов вроде Google и Apple. Но так ли хорошо это для пользователя? И можно ли сказать, что его данные принадлежат ему?

    habr.com/ru/articles/1055364/

    #cryptography #authorization #frontend #javascript #design_principles #ux_design #uxисследования #паттерны #opensource

  14. Login-time #Authorization leaves sensitive cloud data exposed mid-session.

    In this #InfoQ article, Venkata Nedunoori examines a Continuous Authorization Architecture built around:
    • Risk-based policy evaluation
    • Behavioral baselines
    • Privacy-preserving audit trails
    • A phased implementation strategy

    🔗 Read now: bit.ly/44rmyjL

    #CloudComputing #CloudSecurity #ZeroTrust

  15. Login-time leaves sensitive cloud data exposed mid-session.

    In this article, Venkata Nedunoori examines a Continuous Authorization Architecture built around:
    • Risk-based policy evaluation
    • Behavioral baselines
    • Privacy-preserving audit trails
    • A phased implementation strategy

    🔗 Read now: bit.ly/44rmyjL

  16. Learn everything you need to know about Authorization via these 68 free HackerNoon blog posts. hackernoon.com/68-blog-posts-t #authorization

  17. Learn everything you need to know about Authorization via these 68 free HackerNoon blog posts. hackernoon.com/68-blog-posts-t #authorization

  18. Never give in. Never give in. Never, never, never, never, in nothing, great or small, large or petty, never give in except to convictions of honour and good sense. Winston Churchill https://antonmb.com/en/blog/some-ideas-arrive-before-the-market-has-words-for-them #Authentication #Cybersecurity #AI #Authorization #AccessControl #Cryptography #AIAgents #Toqenapp
  19. Democrats say Trump Iran strikes require Congressional authorization

    misryoum.com/us/politics/democ

    NEWYou can now listen to US News Hub articles! Debate on Capitol Hill continues to rage over whether President Donald Trump started a "war" with the strikes he carried out against Iran last weekend, a key consideration for whether...

    #Democrats #say #Trump #Iran #strikes #require #Congressional #authorization #US_News_Hub #misryoum_com

  20. OAuth 2.0 and OIDC Explained with UML
    A blog by Ronald

    The purpose of Open Authorization 2.0 (OAuth 2.0) is to give an application (the "Client") limited access to your data at another service (the "Resource Server"), without having to give your password to that application. When OIDC is added Single Sign-On (SSO) is supported as well. The flow...

    #dev #softwaredevelopment #Security #OpenIDConnect #UML #Authentication #OAuth2.0 #OIDC #Authorization #SSO #SingleSign-On

    jdriven.com/blog/2026/03/OAuth

  21. Over-Privileged AI Drives 4.5 Times Higher Incident Rates.

    Just didn't have much to add to that.

    infosecurity-magazine.com/news

    #ai #authorization

  22. 🚫 Stop checking admin? — it may be creating technical debt.

    Authorization bugs aren’t minor issues.
    They can expose salaries, contracts, or customer data.

    This article breaks down a Kaigi on Rails 2025 talk proposing a permission-centric architecture that scales with real SaaS systems — combining RBAC + ABAC and explicit rules instead of implicit roles.

    Read 👇
    rubystacknews.com/2026/02/17/s

    #Ruby #Rails #Authorization #Security #SaaS #WebDev #KaigiOnRails

  23. A technical disclosure this week detailed a conditional server-side authorization issue affecting Instagram’s mobile web interface.

    Under specific backend states and header conditions, private media metadata and CDN links were reportedly returned without authentication.

    The issue was patched silently, but the lack of formal root-cause acknowledgment has sparked discussion within the security community.

    This case underscores how partial-impact vulnerabilities can be harder to detect - and potentially more concerning - than global failures.

    How do you approach disclosure confidence when fixes arrive without explanation?

    Source: cybersecuritynews.com/instagra

    Join the discussion and follow @technadu for practitioner-focused security coverage.

    #AppSec #Authorization #BugBounty #PrivacyEngineering #Infosec #TechNadu

  24. A common anti-pattern I see in #authorization is trying to shoe-horn everything to fit a few generic permission types (eg CRUD). This almost always leads to awkward compromises and often to violating the principle of least privilege, because each generic permission ends up granting access to a confusing smorgasbord of operations.

    I'd recommend starting with a one-to-one mapping between permissions and exposed #API actions - "increaseTheFrobinator" or whatever. Then carefully aggregate those into more general permission classes if necessary, guided by user needs rather than technical neatness.

  25. I've made SurillyaID available to the public! You can now use SurillyaID as an alternative / primary (whatever you want) login system using OIDC or OAuth 2!

    Developer Portal: developer.surillya.com

    Peertube Tutorial: video.surillya.com/w/fsbWVJU7E

    YouTube tutorial: youtu.be/YQVn3aCgqLQ

    #developer #php #oidc #openid #surillyaid #login #authorization #developers #webdev #html #website