Explore >> Select a destination


You are here

www.authgear.com
| | www.criipto.com
0.9 parsecs away

Travel
| | Learn the differences between session- and token-based authentication, their advantages, and how to implement authentication with OpenID Connect.
| | supertokens.com
1.6 parsecs away

Travel
| | Sessions vs. Tokens: Understanding the Differences in Authentication
| | www.redotheweb.com
1.3 parsecs away

Travel
| | As we're reinventing web applications with SPAs and frontend frameworks, we need to reinvent web application security, too.
| | www.binarysecurity.no
17.3 parsecs away

Travel
| This blog post shows how a user with Reader-level access to an Azure API Management resource actually had the equivalent of Contributor-level access, allowing the user to read, modify and even delete configurations of the resource via the Direct Management API. This was possible because a regular user with read access to the Azure APIM resource was allowed to read the keys of any APIM user via the Azure Resource Manager Rest API. The keys can be used to generate SharedAccessSignatures to authenticate to the Direct Management API, giving access to perform any management operation on the API Management resource.