AJAyush Jaininayushjjainn.hashnode.dev·Sep 19 · 44 min readSecuring Apps: Password Hashing, RBAC, OAuth, and OpenID ConnectIt is 11 at night. Dinner is done, lights are off, and I am in bed with my MacBook Air propped up and my Crinacle Zero 2 IEMs plugged straight into the 3.5mm jack. Netflix is open, The East Palace is 12M
SMSiddhartha Mohapatrainbackend-intro.hashnode.dev·Sep 15 · 7 min readBuilding Secure Applications: From Password Hashing to OAuth and OpenID ConnectHow Does a Website Know Who You Are? When you type a URL into your browser, the server hosting that website has no eyes. How does a website know who you are? For example, when you unlock your phone or00
NKNishchay Kaushikinnkaushik.in·Sep 5 · 12 min readHow to Self-Host Outline Wiki for Your Homelab: The Ultimate Documentation StackEvery homelab begins with high optimism and zero documentation. You spin up a few Docker containers, configure a reverse proxy, assign some IP addresses, and assume you will easily remember how everyt00
MSMohd Sameerinmohd-sameer.hashnode.dev·Aug 31 · 8 min readSecuring Apps: Password Hashing, RBAC, OAuth, and OpenID ConnectHow does a website know who you are? Every time you log into your favorite web application, order food online, or click "Login with Google", a carefully orchestrated sequence of security checks execut00
MSManu Shuklainecorpit.hashnode.dev·Aug 24 · 15 min readEKS raised the OIDC provider cap to 10 on 24 August 2026, but only above Kubernetes 1.32EKS raised the OIDC provider cap to 10 on 24 August 2026, but only above Kubernetes 1.32 Summary. On 24 August 2026 AWS announced that Amazon EKS supports up to 10 external OpenID Connect identity pro00
VPVed Pandeyinvedpandeydev.hashnode.dev·Aug 21 · 17 min readMaster Application SecurityEver thought How does a website remembers you? Why do we hash password? if simple password login was working, then what was the need of OAuth or OIDC (OpenID Connect)? Why roles exists? Today, we are 10
SHSanskriti Harmukhinvultr.hashnode.dev·Aug 6 · 5 min readDeploying ZITADEL – Open-Source Identity and Access Management PlatformZITADEL is an open-source IAM platform supporting OIDC, OAuth 2.0, and SAML, with MFA, passkeys, and SSO built in. This guide deploys it via Docker Compose with PostgreSQL and Traefik-managed TLS, the00
SNSachin Nandanwarinazureguru.net·Aug 3 · 11 min readBuild AI Agents with Microsoft Agent Framework to Access Azure Services Using Entra OAuthImagine a scenario where you have an AI agent that needs to access Azure services, such as Azure Storage. Simply granting the agent open and unrestricted access to Azure resources is not an option. Do10
ABAllen Brooksinlionshead-notes.hashnode.dev·Aug 3 · 9 min readKilling the long-lived tokens in my CI, one exchange at a timeA static API token stored in GitHub Secrets is a breach that has not happened yet. The timer is already running. You do not know how long the fuse is, because a long-lived token's fuse is however long00
SNSachin Nandanwarinazureguru.net·Jul 23 · 14 min readUnderstanding Delegated Tokens vs Application Tokens through Claims-Based Authorization in Microsoft Entra ID My earlier article on securing Azure Storage in ASP.NET core Minimal API's extensively leveraged RBAC access control and through Microsoft Entra ID for user sign-in through OpenID Connect (OIDC) to au20