home.social

#bearer — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #bearer, aggregated by home.social.

fetched live
  1. [Перевод] DPoP: что это такое, как работает и почему Bearer-токенов недостаточно

    Bearer-токен работает слишком просто: кто его получил, тот и авторизован. Именно поэтому утечки токенов регулярно превращаются в реальные инциденты — от CI/CD до облачных хранилищ. В новом переводе от команды Spring АйО рассмотрим, как DPoP меняет эту модель, привязывая токен к ключу клиента, зачем это нужно backend-разработчику и как поднять рабочую реализацию на Keycloak и Quarkus.

    habr.com/ru/companies/spring_a

    #java #kotlin #dpop #ci #cd #bearer #security #безопасность #безопасность_вебприложений #безопасность_в_сети

  2. Everybody who is happy about #Garmin having rolled out #ECG in the #EU and has now #2fa enabled in their account but still want to script a thing or two with #JWT and #Bearer from the site, rejoice… My login script can now deal with that, too… Love #curl and #jq

    github.com/michael-simons/garm

    Now I wait for a new firmware for my watch, because I'm on a beta on which ECG is disabled, lol…

  3. #bearer: Code security scanning tool (#SAST) that discover, filter and prioritize security risks and vulnerabilities leading to sensitive data exposures (PII, PHI, PD). github.com/Bearer/bearer
    #JavaScript #Python #Security