Blogged: Implement client assertions for OAuth client credential flows in ASP.NET Core

Blogged: Implement client assertions for OAuth client credential flows in ASP.NET Core
the role of #oauth in #mcp security
defensiblesystems.substack.com/p/oauths-role-in-mcp-security
tldr: there's going to be lots of problems here
Huge 9.0 release for node-oidc-provider!
Awesome to see #DPoP enabled by default.
https://github.com/panva/node-oidc-provider/releases/tag/v9.0.0
The fraction of my life I spend authenticating to System A so I can subsequently login to System B to get a token for System C is just ridiculous.
@elmiko in my python tests #GeminiAI has been pretty good. So galang doesn't worry me that much. Interestingly multiple AIs struggle with #oauth, eg also #lovable .
There aren't even free standing computers and library employees not respecting documentation standards pisses me off. So i have to check now if another library has a free computer. It's already the second library. In the first ive got #hausverbot because I dont want to be #homeless anymore, see other thread on this masto account.
@netzpolitik_feed Haben die @EUCommission Kollegen schon mal von #oauth gehört? Ein großer Teil der Anfrage-Verwaltung ist damit technisch schon gelöst.
So it seems that there is no way to register a new app on developers.deezer.com?!
How am I supposed to automatically download my playlists now?
Any idea of what I am missing?
Blogged: ASP.NET Core delegated Microsoft OBO access token management (Entra only)
Check your programming frameworks. For example, this is currently only planned in the upcoming major Version of the Spring framework https://github.com/spring-projects/spring-security/issues/16391
At least for the Rust crate openidconnect-rs this is included in the default example: https://docs.rs/openidconnect/latest/openidconnect/
browsing the specs of OAuth 2.1 and found that PKCE is now mandatory for Authorization Code Flow (not only Desktops or frontend-only apps!):
https://datatracker.ietf.org/doc/html/draft-ietf-oauth-v2-1-12
"The authorization code grant is extended with the functionality from PKCE [RFC7636] such that the default method of using the authorization code grant according to this specification requires the addition of the PKCE parameters"
I got #Duende IdentityServer #OAuth working inside an @avaloniaui app. It's pretty easy, thanks to the Duende.IdentityModel package and the browser abstraction. #dotnet
GitHub project maintainers targeted with fake security alert https://www.helpnetsecurity.com/2025/03/17/github-project-maintainers-targeted-with-fake-security-alert/ #accounthijacking #Don'tmiss #Hotstuff #phishing #GitHub #OAuth #News