DEV Community

#authentication

User authentication mechanisms

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Validate the JWT audience claim

Validate the JWT audience claim

Comments
1 min read
Auth Provider Event History vs. Your Audit Log: SOC 2 Evidence

Auth Provider Event History vs. Your Audit Log: SOC 2 Evidence

Comments
6 min read
Beyond Passwords: A Practical Guide to Passkeys in 2026

Beyond Passwords: A Practical Guide to Passkeys in 2026

Comments
2 min read
Social Sign-In JWT Verification: Surviving Key Rotation Without Authentication Outages

Social Sign-In JWT Verification: Surviving Key Rotation Without Authentication Outages

Comments
8 min read
Two RouterOS Bugs, One Escalation Path: What CVE-2026-67277 and CVE-2026-86060 Mean for Edge Routers

Two RouterOS Bugs, One Escalation Path: What CVE-2026-67277 and CVE-2026-86060 Mean for Edge Routers

Comments
4 min read
Your AI Gateway Is Holding the Keys: Hardening Self-Hosted LLM Infrastructure After the LiteLLM and Starlette KEV Additions

Your AI Gateway Is Holding the Keys: Hardening Self-Hosted LLM Infrastructure After the LiteLLM and Starlette KEV Additions

Comments
3 min read
The Bug That Sat Fixed for Three Years: Proxmox VE's Authentication Bypass and the Cost of Unsupported Hypervisors

The Bug That Sat Fixed for Three Years: Proxmox VE's Authentication Bypass and the Cost of Unsupported Hypervisors

Comments
3 min read
We changed one timeout from 30 to 480 and back to 30. In between, it stopped meaning the same thing

We changed one timeout from 30 to 480 and back to 30. In between, it stopped meaning the same thing

Comments
19 min read
Passkeys vs Passwords: Why Passkeys Will Kill Passwords

Passkeys vs Passwords: Why Passkeys Will Kill Passwords

Comments
3 min read
nixamp 0.17: a room with a door, a ticket and a login

nixamp 0.17: a room with a door, a ticket and a login

Comments
3 min read
Password Strength + Crack Time Estimators

Password Strength + Crack Time Estimators

Comments
12 min read
Your Session Cookie Is Basically a Temporary Password - Part 1

Your Session Cookie Is Basically a Temporary Password - Part 1

Comments
6 min read
When the Default Configuration Is the Vulnerability: JFrog Artifactory's Empty Join Key and the Supply-Chain Blast Radius

When the Default Configuration Is the Vulnerability: JFrog Artifactory's Empty Join Key and the Supply-Chain Blast Radius

Comments
4 min read
ProfessorOS

ProfessorOS

Comments
3 min read
When an Authentication Filter Reads the URL Instead of the Route: Lessons from CVE-2026-49869 in Kestra

When an Authentication Filter Reads the URL Instead of the Route: Lessons from CVE-2026-49869 in Kestra

Comments
4 min read
👋 Sign in for the ability to sort posts by relevant, latest, or top.