Core Security Precept: Principle of Least Privilege
The word “rule” is overused; so, I went with “precept” — a rule or principle that defines how one should think or act.
Read article: Core Security Precept: Principle of Least Privilege32 articles tagged Authorization.
The word “rule” is overused; so, I went with “precept” — a rule or principle that defines how one should think or act.
Read article: Core Security Precept: Principle of Least PrivilegeYour production environment should be isolated from your non-production environments. In fact, every application environment should be isolated from every other environment. Sounds simple in practice, but how does one accomplish this? Through a multi-layered isolation strategy:
Read article: Achieving Application Environment IsolationBut, let’s face it, you’re probably going to do it anyway.
Read article: No, You Shouldn’t Use Production Data For TestingPrivacy (and Digital Privacy) is one of those terms that I’ve thrown around a lot in the last few years. However, I never took the time to define it.
Read article: What Is Digital Privacy?First, let’s get the usual introductions out of the way. For an in-depth discussion of what Authorization is, check out this post. For a complete introduction to Authorization concepts see my Authorization Series. This post continues my long-running Authorization Series. In this post, we’re going…
Read article: Application Front-Ends Must Not Make Authorization DecisionsThis blog post continues our discussion of Authorization in the API space. It will explore common authorization patterns with API Gateways and the backend API Providers. Generally, the API Gateway will apply a Coarse Grained Authorization (CGA) decision and the API Provider will implement Fine…
Read article: Making Authorization DecisionsThis post continues where “SECURELY USING THE OIDC AUTHORIZATION CODE FLOW AND A PUBLIC CLIENT WITH SINGLE PAGE APPLICATIONS” left off on the topic of securing Single Page Applications (SPAs). That post describes an architecture where the SPA running in the browser (User Agent)is acting as the…
Read article: More Single Page Application (SPA) and OAuth2 ThoughtsThis post contains links to all the articles about authorization that I have written.
Read article: Authorization SeriesThis blog post was originally published as “SECURELY USING THE OIDC AUTHORIZATION CODE FLOW AND A PUBLIC CLIENT WITH SINGLE PAGE APPLICATIONS” on the Ping Identity blog.
Read article: SECURELY USING THE OIDC AUTHORIZATION CODE FLOW AND A PUBLIC CLIENT WITH SINGLE PAGE APPLICATIONSEarlier this year, I was working on a project that was using AWS Cognito (as the identity stack) and the AWS API Gateway (as the front-door to all of the API calls). AWS Cognito is a relatively new player in the identity space. It doesn’t support the full OAuth2 or OpenID Connect specs, but, does…
Read article: OpenID Connect Authorization Code Flow with AWS Cognito