home.social

#fedcm — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #fedcm, aggregated by home.social.

fetched live
  1. Currently implementing the Federated Credential Management API
    w3c-fedid.github.io/FedCM/

    Flow and Benefits
    corbado.com/blog/fedcm-federat

    Funny Quote
    „Axel Springer (Welt, Bild): German media giant with full FedCM deployment:
    - 14x increase in monthly registrations after implementing FedCM“

    #FedCM #OAuth #cimd #ActivityPub #fedidev

  2. Currently implementing the Federated Credential Management API
    w3c-fedid.github.io/FedCM/

    Flow and Benefits
    corbado.com/blog/fedcm-federat

    Funny Quote
    „Axel Springer (Welt, Bild): German media giant with full FedCM deployment:
    - 14x increase in monthly registrations after implementing FedCM“

    #FedCM #OAuth #cimd #ActivityPub #fedidev

  3. OAuth‑сервер, который не хранит пользователей

    Наш OAuth-сервер не хранит профиль пользователя и практически ничего о нём не знает. Он знает только IdP-личность («вы вошли через Google под таким-то аккаунтом»), а внутренний id , роль и имя живут в продуктовом бэкенде. Сшивают их два кастомных гранта: первый вкладывает в токен подписанный профиль, не зная его содержимого, а второй разменивает основной токен на веер узких производных, по одному на аудиторию. Кроме того, в статье объясняется, почему FedCM может создавать больше проблем, чем решать, и как эти проблемы обходятся с помощью Service Worker. Если вам интересно, как всё это работает в SaaS, прошу под кат.

    habr.com/ru/articles/1063816/

    #OAuth_20 #OpenID_Connect #JWT #FedCM #Service_Worker #token_exchange #PKCE #JWKS

  4. One thing I really like about ATProto/Atmosphere is the concept of a PDS, or Personal Data Server, storing all your account data.

    The other day someone announced bookhive.buzz, basically ATProto take on bookwyrm.social, but unlike Bookwyrm, which requires you to create a separate account, Bookhive lets you log in with your PDS, most commonly your Bluesky account.

    That's actually pretty neat.

    And we could have something similar with Federated Credential Management (FedCM).

    developer.mozilla.org/en-US/do

    Here's a GitHub issue requesting this for Mastodon:

    github.com/mastodon/mastodon/i

    #fediverse #mastodon #FedCM #indieauth #SocialMedia #ATProto #PDS

  5. One thing I really like about ATProto/Atmosphere is the concept of a PDS, or Personal Data Server, storing all your account data.

    The other day someone announced bookhive.buzz, basically ATProto take on bookwyrm.social, but unlike Bookwyrm, which requires you to create a separate account, Bookhive lets you log in with your PDS, most commonly your Bluesky account.

    That's actually pretty neat.

    And we could have something similar with Federated Credential Management (FedCM).

    developer.mozilla.org/en-US/do

    Here's a GitHub issue requesting this for Mastodon:

    github.com/mastodon/mastodon/i

    #fediverse #mastodon #FedCM #indieauth #SocialMedia #ATProto #PDS

  6. Have you looked at FedCM yet?

    Here is short video explaining what it is, and why the idp-registration feature could matter a lot for decentralized identity and login UX.

    Learn more at liquid.surf/fedcm

    #FedCM #Identity #OpenWeb #DecentralizedWeb #indieweb

  7. Have you looked at FedCM yet?

    Here is short video explaining what it is, and why the idp-registration feature could matter a lot for decentralized identity and login UX.

    Learn more at liquid.surf/fedcm

    #FedCM #Identity #OpenWeb #DecentralizedWeb #indieweb

  8. This is pretty darn cool. I don't know a lot about IdP registration, but it looks like this could improve the Sign-In flow in decentralized ecosystems.

    Did I copy pasta a lot of that to try and entice you to watch this video? Yes, yes I did.

    spectra.video/w/nZsKQ6jJkwnZ62

    #idp #decentralization #signin #fedcm

  9. This is pretty darn cool. I don't know a lot about IdP registration, but it looks like this could improve the Sign-In flow in decentralized ecosystems.

    Did I copy pasta a lot of that to try and entice you to watch this video? Yes, yes I did.

    spectra.video/w/nZsKQ6jJkwnZ62

    #idp #decentralization #signin #fedcm

  10. Entendi corretamente?

    O FedCM usa a própria API do navegador pra criar pop-up de login sem ter que enviar cookies ou sessão pras plataformas de login social?

    Dá pra validar o usuário no IdP institucional sem expor tanto as contas aos rastreadores dos sites

    developer.chrome.com/docs/iden

    #fedCM #duvida

  11. Entendi corretamente?

    O FedCM usa a própria API do navegador pra criar pop-up de login sem ter que enviar cookies ou sessão pras plataformas de login social?

    Dá pra validar o usuário no IdP institucional sem expor tanto as contas aos rastreadores dos sites

    developer.chrome.com/docs/iden

    #fedCM #duvida

  12. #FedCM is a proposed standard API for frictionless, privacy-preserving 𝐟𝐞𝐝𝐞𝐫𝐚𝐭𝐞𝐝 𝐥𝐨𝐠𝐢𝐧 on the web.

    👉 Simplifies login for both 𝐮𝐬𝐞𝐫𝐬 & 𝐝𝐞𝐯𝐞𝐥𝐨𝐩𝐞𝐫𝐬.
    ✅ Already supported in 𝐂𝐡𝐫𝐨𝐦𝐢𝐮𝐦 𝐛𝐫𝐨𝐰𝐬𝐞𝐫𝐬.

    📰 Dive deeper in this #InfoQ article by Dan Moore: bit.ly/4n9BKcY

    #WebDevelopment #SoftwareArchitecture #SoftwareDevelopment

  13. is a proposed standard API for frictionless, privacy-preserving 𝐟𝐞𝐝𝐞𝐫𝐚𝐭𝐞𝐝 𝐥𝐨𝐠𝐢𝐧 on the web.

    👉 Simplifies login for both 𝐮𝐬𝐞𝐫𝐬 & 𝐝𝐞𝐯𝐞𝐥𝐨𝐩𝐞𝐫𝐬.
    ✅ Already supported in 𝐂𝐡𝐫𝐨𝐦𝐢𝐮𝐦 𝐛𝐫𝐨𝐰𝐬𝐞𝐫𝐬.

    📰 Dive deeper in this article by Dan Moore: bit.ly/4n9BKcY

  14. Awesome to see Shop using #FedCM in the wild!

  15. Awesome to see Shop using #FedCM in the wild!

  16. What's a good example for #FedCM in the wild? Are there any yet?

    FedCM=Federated Credential Management developer.mozilla.org/en-US/do

  17. What's a good example for #FedCM in the wild? Are there any yet?

    FedCM=Federated Credential Management developer.mozilla.org/en-US/do

  18. Back in June I wrote about an exciting confluence of digital auth tech:

    (1) The commodification of #OIDC infrastructure, (2) the emergence of #FedCM, (3) and the compatibility of both with #indieauth .

    In short, it is now easier than ever to log into web applications using your own website as an identity provider. Or at least, it would be, if your favorite web apps supported these agency-enhancing technologies.

    blog.erlend.sh/indie-social-si

    #opensource #indieweb #identity

  19. Back in June I wrote about an exciting confluence of digital auth tech:

    (1) The commodification of #OIDC infrastructure, (2) the emergence of #FedCM, (3) and the compatibility of both with #indieauth .

    In short, it is now easier than ever to log into web applications using your own website as an identity provider. Or at least, it would be, if your favorite web apps supported these agency-enhancing technologies.

    blog.erlend.sh/indie-social-si

    #opensource #indieweb #identity

  20. Anyone interested in single sign-on / #SSO? Want a new toy to play with? I've been experimenting with it recently, and now I've got something to share: an experimental demo of how a "Sign in with the Fediverse" mechanism might work.

    If you have a Mastodon or Hubzilla account, or an IndieAuth-style self-hosted identity, I'd like to invite you to try and sign in to my test site at login.mythik.co.uk.

    Headline features:
    • User authentication/authorization based on the Ory tools.
    • Supports signing in using an existing Fediverse (or other) account - or one you host yourself
    • Open source - well, not yet, but it could be, if people are interested in it
    • Written by a non-expert! Woefully insecure! All manner of attacks, just waiting to be found! Invite your security expert friends to the party, and laugh together at the n00b! Fun for all the family!

    Supported identity providers include:

    (There's a chance Streams might work, too.)

    Protocols supported:

    If you can get it to work - share a screenshot and let me know what you think!

    (I'll try to keep this running for a while, but I can't guarantee it - partly because I haven't finished trying to attack it yet. If I have to take it down for some reason, I'll edit this post to say so.)
  21. Anyone interested in single sign-on / #SSO? Want a new toy to play with? I've been experimenting with it recently, and now I've got something to share: an experimental demo of how a "Sign in with the Fediverse" mechanism might work.

    If you have a Mastodon or Hubzilla account, or an IndieAuth-style self-hosted identity, I'd like to invite you to try and sign in to my test site at login.mythik.co.uk.

    Headline features:
    • User authentication/authorization based on the Ory tools.
    • Supports signing in using an existing Fediverse (or other) account - or one you host yourself
    • Open source - well, not yet, but it could be, if people are interested in it
    • Written by a non-expert! Woefully insecure! All manner of attacks, just waiting to be found! Invite your security expert friends to the party, and laugh together at the n00b! Fun for all the family!

    Supported identity providers include:

    (There's a chance Streams might work, too.)

    Protocols supported:

    If you can get it to work - share a screenshot and let me know what you think!

    (I'll try to keep this running for a while, but I can't guarantee it - partly because I haven't finished trying to attack it yet. If I have to take it down for some reason, I'll edit this post to say so.)
  22. Just learned about the "Federated Credential Management API" #FedCM - a new proposal that adds browser support for managing delegated authentication workflows #OAuth #OIDC. It already looks great, but could be expanded with user-centric identity provider registration for more decentralization, as explained here: liquid.surf/2024/2/7/Can-FedCM

  23. Just learned about the "Federated Credential Management API" #FedCM - a new proposal that adds browser support for managing delegated authentication workflows #OAuth #OIDC. It already looks great, but could be expanded with user-centric identity provider registration for more decentralization, as explained here: liquid.surf/2024/2/7/Can-FedCM

  24. Ever wondered if #FedCM supports #authorization ? It's coming!
    Starting in Chrome 126, you can sign up for an origin trial and try it on your domain with the Continuation API. Along with the button flow we've introduced in the previous announcement, FedCM based sign-in flow will become even more streamlined. There are a few more exciting updates as well.
    Checkout the details in this blog post, try it yourself and let us know what you think:
    developers.google.com/privacy-

  25. Ever wondered if #FedCM supports #authorization ? It's coming!
    Starting in Chrome 126, you can sign up for an origin trial and try it on your domain with the Continuation API. Along with the button flow we've introduced in the previous announcement, FedCM based sign-in flow will become even more streamlined. There are a few more exciting updates as well.
    Checkout the details in this blog post, try it yourself and let us know what you think:
    developers.google.com/privacy-

  26. Well this is moving quickly! You can now spin up FedCM on your own website and log in to https://webmention.io thanks to this open source project from Sam Goto! This is so much better than having to type out your website or even email address when logging in! Full instructions here:

    https://github.com/fedidcg/FedCM/issues/240#issuecomment-2118606184
  27. Well this is moving quickly! You can now spin up FedCM on your own website and log in to https://webmention.io thanks to this open source project from Sam Goto! This is so much better than having to type out your website or even email address when logging in! Full instructions here:

    https://github.com/fedidcg/FedCM/issues/240#issuecomment-2118606184
  28. Just did a test, and I think we may be able to implement FedCM in Mastodon. It seems that you can actually create Doorkeeper Applications with a client_id that's a URL, rather than having it generate a unique client_id for you.

    However, where it fails is that you don't get a unique client_id, so registering the same client again fails with a duplicate record error (maybe this is intentional?)

    I guess FedCM client_id's don't have a client_secret at all to use…

    #Mastodon #MastoDev #FedCM

  29. Just did a test, and I think we may be able to implement FedCM in Mastodon. It seems that you can actually create Doorkeeper Applications with a client_id that's a URL, rather than having it generate a unique client_id for you.

    However, where it fails is that you don't get a unique client_id, so registering the same client again fails with a duplicate record error (maybe this is intentional?)

    I guess FedCM client_id's don't have a client_secret at all to use…

    #Mastodon #MastoDev #FedCM

  30. This weekend I built a prototype of using FedCM for IndieAuth! This gets rid of the need to enter your domain when logging in to websites using IndieAuth! Demo video and notes here: https://aaronparecki.com/2024/05/12/3/fedcm-for-indieauth
  31. This weekend I built a prototype of using FedCM for IndieAuth! This gets rid of the need to enter your domain when logging in to websites using IndieAuth! Demo video and notes here: https://aaronparecki.com/2024/05/12/3/fedcm-for-indieauth
  32. #FedCM is a new #browser API that enables #identity #federation without relying on third-party #cookies. With an upcoming new feature called Button Mode API, FedCM will be able to display a modal dialog and let the user sign in to the identity provider before signing into the relying party.
    You can start experimenting with this new API from #Chrome 125 which is currently in beta and see how effectively it works. Learn more about this new API at developers.google.com/privacy-

  33. #FedCM is a new #browser API that enables #identity #federation without relying on third-party #cookies. With an upcoming new feature called Button Mode API, FedCM will be able to display a modal dialog and let the user sign in to the identity provider before signing into the relying party.
    You can start experimenting with this new API from #Chrome 125 which is currently in beta and see how effectively it works. Learn more about this new API at developers.google.com/privacy-

  34. Just finished a #FedCM 101 session at the OAuth Security Workshop with Sam Goto. So many great discussions and questions!

    Slides available at tcslides.link/OSW24-FedCM101

    #osw #oauthsecurityworkshop

  35. Just finished a #FedCM 101 session at the OAuth Security Workshop with Sam Goto. So many great discussions and questions!

    Slides available at tcslides.link/OSW24-FedCM101

    #osw #oauthsecurityworkshop

  36. From Chrome 123, you can use the Domain Hints alongside the Federated Credential Management API (FedCM). With the Domain Hint API, developers can provide a better user experience by only showing the federated login accounts from the domain that they accept.
    buff.ly/3wFmzTD

    #FedCM is an emerging browser API that allows identity federation without relying on third-party cookies. Learn more about FedCM from here: buff.ly/3wEkHe2

    #authentication #openid #oauth

  37. From Chrome 123, you can use the Domain Hints alongside the Federated Credential Management API (FedCM). With the Domain Hint API, developers can provide a better user experience by only showing the federated login accounts from the domain that they accept.
    buff.ly/3wFmzTD

    #FedCM is an emerging browser API that allows identity federation without relying on third-party cookies. Learn more about FedCM from here: buff.ly/3wEkHe2

    #authentication #openid #oauth

  38. This week our own David Hübner travelled to the US as an advocate for the German research community to join a #REFEDS hackathon, and discuss the future of #3rdPartyCookies and their meaning for #SAML, #OIDC and #FedCM with browser vendors like @chrome

    For more info on #FedCM check out fedidcg.github.io/FedCM/

  39. It would be really nice if opening a mastodon.wrongserver.social link would automatically open the toot in the Mastodon PWA I've installed. I think you'd need a central coordination domain to do it with 3p cookies, and those are going away anyway. @sgoto, can #FedCm do it? Could protocol handlers, maybe, if we expect the installed server to register mastodon: or activitypub: or something?

    #WebStandards