#fedcm — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #fedcm, aggregated by home.social.
-
Currently implementing the Federated Credential Management API
https://w3c-fedid.github.io/FedCM/Flow and Benefits
https://www.corbado.com/blog/fedcm-federated-credential-management-apiFunny Quote
„Axel Springer (Welt, Bild): German media giant with full FedCM deployment:
- 14x increase in monthly registrations after implementing FedCM“ -
Currently implementing the Federated Credential Management API
https://w3c-fedid.github.io/FedCM/Flow and Benefits
https://www.corbado.com/blog/fedcm-federated-credential-management-apiFunny Quote
„Axel Springer (Welt, Bild): German media giant with full FedCM deployment:
- 14x increase in monthly registrations after implementing FedCM“ -
OAuth‑сервер, который не хранит пользователей
Наш OAuth-сервер не хранит профиль пользователя и практически ничего о нём не знает. Он знает только IdP-личность («вы вошли через Google под таким-то аккаунтом»), а внутренний id , роль и имя живут в продуктовом бэкенде. Сшивают их два кастомных гранта: первый вкладывает в токен подписанный профиль, не зная его содержимого, а второй разменивает основной токен на веер узких производных, по одному на аудиторию. Кроме того, в статье объясняется, почему FedCM может создавать больше проблем, чем решать, и как эти проблемы обходятся с помощью Service Worker. Если вам интересно, как всё это работает в SaaS, прошу под кат.
https://habr.com/ru/articles/1063816/
#OAuth_20 #OpenID_Connect #JWT #FedCM #Service_Worker #token_exchange #PKCE #JWKS
-
One thing I really like about ATProto/Atmosphere is the concept of a PDS, or Personal Data Server, storing all your account data.
The other day someone announced https://bookhive.buzz, basically ATProto take on https://bookwyrm.social, but unlike Bookwyrm, which requires you to create a separate account, Bookhive lets you log in with your PDS, most commonly your Bluesky account.
That's actually pretty neat.
And we could have something similar with Federated Credential Management (FedCM).
https://developer.mozilla.org/en-US/docs/Web/API/FedCM_API
Here's a GitHub issue requesting this for Mastodon:
https://github.com/mastodon/mastodon/issues/4800
#fediverse #mastodon #FedCM #indieauth #SocialMedia #ATProto #PDS
-
One thing I really like about ATProto/Atmosphere is the concept of a PDS, or Personal Data Server, storing all your account data.
The other day someone announced https://bookhive.buzz, basically ATProto take on https://bookwyrm.social, but unlike Bookwyrm, which requires you to create a separate account, Bookhive lets you log in with your PDS, most commonly your Bluesky account.
That's actually pretty neat.
And we could have something similar with Federated Credential Management (FedCM).
https://developer.mozilla.org/en-US/docs/Web/API/FedCM_API
Here's a GitHub issue requesting this for Mastodon:
https://github.com/mastodon/mastodon/issues/4800
#fediverse #mastodon #FedCM #indieauth #SocialMedia #ATProto #PDS
-
Have you looked at FedCM yet?
Here is short video explaining what it is, and why the idp-registration feature could matter a lot for decentralized identity and login UX.
Learn more at https://liquid.surf/fedcm
-
Have you looked at FedCM yet?
Here is short video explaining what it is, and why the idp-registration feature could matter a lot for decentralized identity and login UX.
Learn more at https://liquid.surf/fedcm
-
This is pretty darn cool. I don't know a lot about IdP registration, but it looks like this could improve the Sign-In flow in decentralized ecosystems.
Did I copy pasta a lot of that to try and entice you to watch this video? Yes, yes I did.
-
This is pretty darn cool. I don't know a lot about IdP registration, but it looks like this could improve the Sign-In flow in decentralized ecosystems.
Did I copy pasta a lot of that to try and entice you to watch this video? Yes, yes I did.
-
Entendi corretamente?
O FedCM usa a própria API do navegador pra criar pop-up de login sem ter que enviar cookies ou sessão pras plataformas de login social?
Dá pra validar o usuário no IdP institucional sem expor tanto as contas aos rastreadores dos sites
https://developer.chrome.com/docs/identity/fedcm/overview?hl=pt-br
-
Entendi corretamente?
O FedCM usa a própria API do navegador pra criar pop-up de login sem ter que enviar cookies ou sessão pras plataformas de login social?
Dá pra validar o usuário no IdP institucional sem expor tanto as contas aos rastreadores dos sites
https://developer.chrome.com/docs/identity/fedcm/overview?hl=pt-br
-
#FedCM is a proposed standard API for frictionless, privacy-preserving 𝐟𝐞𝐝𝐞𝐫𝐚𝐭𝐞𝐝 𝐥𝐨𝐠𝐢𝐧 on the web.
👉 Simplifies login for both 𝐮𝐬𝐞𝐫𝐬 & 𝐝𝐞𝐯𝐞𝐥𝐨𝐩𝐞𝐫𝐬.
✅ Already supported in 𝐂𝐡𝐫𝐨𝐦𝐢𝐮𝐦 𝐛𝐫𝐨𝐰𝐬𝐞𝐫𝐬.📰 Dive deeper in this #InfoQ article by Dan Moore: https://bit.ly/4n9BKcY
-
#FedCM is a proposed standard API for frictionless, privacy-preserving 𝐟𝐞𝐝𝐞𝐫𝐚𝐭𝐞𝐝 𝐥𝐨𝐠𝐢𝐧 on the web.
👉 Simplifies login for both 𝐮𝐬𝐞𝐫𝐬 & 𝐝𝐞𝐯𝐞𝐥𝐨𝐩𝐞𝐫𝐬.
✅ Already supported in 𝐂𝐡𝐫𝐨𝐦𝐢𝐮𝐦 𝐛𝐫𝐨𝐰𝐬𝐞𝐫𝐬.📰 Dive deeper in this #InfoQ article by Dan Moore: https://bit.ly/4n9BKcY
-
-
-
What's a good example for #FedCM in the wild? Are there any yet?
FedCM=Federated Credential Management https://developer.mozilla.org/en-US/docs/Web/API/FedCM_API
-
What's a good example for #FedCM in the wild? Are there any yet?
FedCM=Federated Credential Management https://developer.mozilla.org/en-US/docs/Web/API/FedCM_API
-
Back in June I wrote about an exciting confluence of digital auth tech:
(1) The commodification of #OIDC infrastructure, (2) the emergence of #FedCM, (3) and the compatibility of both with #indieauth .
In short, it is now easier than ever to log into web applications using your own website as an identity provider. Or at least, it would be, if your favorite web apps supported these agency-enhancing technologies.
https://blog.erlend.sh/indie-social-sign-in-could-go-mainstream
-
Back in June I wrote about an exciting confluence of digital auth tech:
(1) The commodification of #OIDC infrastructure, (2) the emergence of #FedCM, (3) and the compatibility of both with #indieauth .
In short, it is now easier than ever to log into web applications using your own website as an identity provider. Or at least, it would be, if your favorite web apps supported these agency-enhancing technologies.
https://blog.erlend.sh/indie-social-sign-in-could-go-mainstream
-
Anyone interested in single sign-on / #SSO? Want a new toy to play with? I've been experimenting with it recently, and now I've got something to share: an experimental demo of how a "Sign in with the Fediverse" mechanism might work.
If you have a Mastodon or Hubzilla account, or an IndieAuth-style self-hosted identity, I'd like to invite you to try and sign in to my test site at login.mythik.co.uk.
Headline features:- User authentication/authorization based on the Ory tools.
- Supports signing in using an existing Fediverse (or other) account - or one you host yourself
- Open source - well, not yet, but it could be, if people are interested in it
- Written by a non-expert! Woefully insecure! All manner of attacks, just waiting to be found! Invite your security expert friends to the party, and laugh together at the n00b! Fun for all the family!
Supported identity providers include:- Mastodon (must be a recent version that includes this pull request). mastodon.social is known to work.
- Hubzilla (any version). zotum.net is known to work.
- #IndieAuth / #FedCM
- Another instance of itself, using OpenID Connect
(There's a chance Streams might work, too.)
Protocols supported:- #OIDC Discovery
- Client ID Metadata Document
- FedCM for IndieAuth
- #OpenWebAuth
- A method using the Mastodon API
- Classic (non-FedCM) IndieAuth (if you're lucky; I found this very hard to test, and had various problems with it)
- My original experiments used Dynamic Client Registration but I've moved away from this.
If you can get it to work - share a screenshot and let me know what you think!
(I'll try to keep this running for a while, but I can't guarantee it - partly because I haven't finished trying to attack it yet. If I have to take it down for some reason, I'll edit this post to say so.) -
Anyone interested in single sign-on / #SSO? Want a new toy to play with? I've been experimenting with it recently, and now I've got something to share: an experimental demo of how a "Sign in with the Fediverse" mechanism might work.
If you have a Mastodon or Hubzilla account, or an IndieAuth-style self-hosted identity, I'd like to invite you to try and sign in to my test site at login.mythik.co.uk.
Headline features:- User authentication/authorization based on the Ory tools.
- Supports signing in using an existing Fediverse (or other) account - or one you host yourself
- Open source - well, not yet, but it could be, if people are interested in it
- Written by a non-expert! Woefully insecure! All manner of attacks, just waiting to be found! Invite your security expert friends to the party, and laugh together at the n00b! Fun for all the family!
Supported identity providers include:- Mastodon (must be a recent version that includes this pull request). mastodon.social is known to work.
- Hubzilla (any version). zotum.net is known to work.
- #IndieAuth / #FedCM
- Another instance of itself, using OpenID Connect
(There's a chance Streams might work, too.)
Protocols supported:- #OIDC Discovery
- Client ID Metadata Document
- FedCM for IndieAuth
- #OpenWebAuth
- A method using the Mastodon API
- Classic (non-FedCM) IndieAuth (if you're lucky; I found this very hard to test, and had various problems with it)
- My original experiments used Dynamic Client Registration but I've moved away from this.
If you can get it to work - share a screenshot and let me know what you think!
(I'll try to keep this running for a while, but I can't guarantee it - partly because I haven't finished trying to attack it yet. If I have to take it down for some reason, I'll edit this post to say so.) -
Just learned about the "Federated Credential Management API" #FedCM - a new proposal that adds browser support for managing delegated authentication workflows #OAuth #OIDC. It already looks great, but could be expanded with user-centric identity provider registration for more decentralization, as explained here: https://www.liquid.surf/2024/2/7/Can-FedCM-improve-Solid-login-flow
-
Just learned about the "Federated Credential Management API" #FedCM - a new proposal that adds browser support for managing delegated authentication workflows #OAuth #OIDC. It already looks great, but could be expanded with user-centric identity provider registration for more decentralization, as explained here: https://www.liquid.surf/2024/2/7/Can-FedCM-improve-Solid-login-flow
-
Ever wondered if #FedCM supports #authorization ? It's coming!
Starting in Chrome 126, you can sign up for an origin trial and try it on your domain with the Continuation API. Along with the button flow we've introduced in the previous announcement, FedCM based sign-in flow will become even more streamlined. There are a few more exciting updates as well.
Checkout the details in this blog post, try it yourself and let us know what you think:
https://developers.google.com/privacy-sandbox/blog/fedcm-chrome-126-updates -
Ever wondered if #FedCM supports #authorization ? It's coming!
Starting in Chrome 126, you can sign up for an origin trial and try it on your domain with the Continuation API. Along with the button flow we've introduced in the previous announcement, FedCM based sign-in flow will become even more streamlined. There are a few more exciting updates as well.
Checkout the details in this blog post, try it yourself and let us know what you think:
https://developers.google.com/privacy-sandbox/blog/fedcm-chrome-126-updates -
Well this is moving quickly! You can now spin up FedCM on your own website and log in to https://webmention.io thanks to this open source project from Sam Goto! This is so much better than having to type out your website or even email address when logging in! Full instructions here:
https://github.com/fedidcg/FedCM/issues/240#issuecomment-2118606184 -
Well this is moving quickly! You can now spin up FedCM on your own website and log in to https://webmention.io thanks to this open source project from Sam Goto! This is so much better than having to type out your website or even email address when logging in! Full instructions here:
https://github.com/fedidcg/FedCM/issues/240#issuecomment-2118606184 -
Just did a test, and I think we may be able to implement FedCM in Mastodon. It seems that you can actually create Doorkeeper Applications with a client_id that's a URL, rather than having it generate a unique client_id for you.
However, where it fails is that you don't get a unique client_id, so registering the same client again fails with a duplicate record error (maybe this is intentional?)
I guess FedCM client_id's don't have a client_secret at all to use…
-
Just did a test, and I think we may be able to implement FedCM in Mastodon. It seems that you can actually create Doorkeeper Applications with a client_id that's a URL, rather than having it generate a unique client_id for you.
However, where it fails is that you don't get a unique client_id, so registering the same client again fails with a duplicate record error (maybe this is intentional?)
I guess FedCM client_id's don't have a client_secret at all to use…
-
This weekend I built a prototype of using FedCM for IndieAuth! This gets rid of the need to enter your domain when logging in to websites using IndieAuth! Demo video and notes here: https://aaronparecki.com/2024/05/12/3/fedcm-for-indieauth -
This weekend I built a prototype of using FedCM for IndieAuth! This gets rid of the need to enter your domain when logging in to websites using IndieAuth! Demo video and notes here: https://aaronparecki.com/2024/05/12/3/fedcm-for-indieauth -
#FedCM is a new #browser API that enables #identity #federation without relying on third-party #cookies. With an upcoming new feature called Button Mode API, FedCM will be able to display a modal dialog and let the user sign in to the identity provider before signing into the relying party.
You can start experimenting with this new API from #Chrome 125 which is currently in beta and see how effectively it works. Learn more about this new API at https://developers.google.com/privacy-sandbox/blog/fedcm-chrome-125-updates -
#FedCM is a new #browser API that enables #identity #federation without relying on third-party #cookies. With an upcoming new feature called Button Mode API, FedCM will be able to display a modal dialog and let the user sign in to the identity provider before signing into the relying party.
You can start experimenting with this new API from #Chrome 125 which is currently in beta and see how effectively it works. Learn more about this new API at https://developers.google.com/privacy-sandbox/blog/fedcm-chrome-125-updates -
Just finished a #FedCM 101 session at the OAuth Security Workshop with Sam Goto. So many great discussions and questions!
Slides available at https://tcslides.link/OSW24-FedCM101
-
Just finished a #FedCM 101 session at the OAuth Security Workshop with Sam Goto. So many great discussions and questions!
Slides available at https://tcslides.link/OSW24-FedCM101
-
From Chrome 123, you can use the Domain Hints alongside the Federated Credential Management API (FedCM). With the Domain Hint API, developers can provide a better user experience by only showing the federated login accounts from the domain that they accept.
https://buff.ly/3wFmzTD#FedCM is an emerging browser API that allows identity federation without relying on third-party cookies. Learn more about FedCM from here: https://buff.ly/3wEkHe2
-
From Chrome 123, you can use the Domain Hints alongside the Federated Credential Management API (FedCM). With the Domain Hint API, developers can provide a better user experience by only showing the federated login accounts from the domain that they accept.
https://buff.ly/3wFmzTD#FedCM is an emerging browser API that allows identity federation without relying on third-party cookies. Learn more about FedCM from here: https://buff.ly/3wEkHe2
-
This week our own David Hübner travelled to the US as an advocate for the German research community to join a #REFEDS hackathon, and discuss the future of #3rdPartyCookies and their meaning for #SAML, #OIDC and #FedCM with browser vendors like @chrome
For more info on #FedCM check out https://fedidcg.github.io/FedCM/
-
It would be really nice if opening a mastodon.wrongserver.social link would automatically open the toot in the Mastodon PWA I've installed. I think you'd need a central coordination domain to do it with 3p cookies, and those are going away anyway. @sgoto, can #FedCm do it? Could protocol handlers, maybe, if we expect the installed server to register mastodon: or activitypub: or something?
-
Chromium will get a new privacy preserving Option called FedCM
Flag
#fedcm