#authorization

2026-01-29

Trouble in Port Coquitlam neighbourhood after care provider, resident moves in
The City of Port Coquitlam told Global News that the house isn't authorized to be used for this service and neighbours have been concerned about what's happening.
#neighborhood #concern #authorization #PortCoquitlam #Health #Politics
globalnews.ca/news/11642383/po

Trouble in Port Coquitlam neighbourhood after care provider, resident moves in
The City of Port Coquitlam told Global News that the house isn't authorized to be used for this service and neighbours have been concerned about what's happening.
#neighborhood #concern #authorization #PortCoquitlam #Health #Politics
globalnews.ca/news/11642383/po

2026-01-27

A technical disclosure this week detailed a conditional server-side authorization issue affecting Instagram’s mobile web interface.

Under specific backend states and header conditions, private media metadata and CDN links were reportedly returned without authentication.

The issue was patched silently, but the lack of formal root-cause acknowledgment has sparked discussion within the security community.

This case underscores how partial-impact vulnerabilities can be harder to detect - and potentially more concerning - than global failures.

How do you approach disclosure confidence when fixes arrive without explanation?

Source: cybersecuritynews.com/instagra

Join the discussion and follow @technadu for practitioner-focused security coverage.

#AppSec #Authorization #BugBounty #PrivacyEngineering #Infosec #TechNadu

New Instagram Vulnerability Exposes Private Posts to Anyone
2026-01-21

A common anti-pattern I see in #authorization is trying to shoe-horn everything to fit a few generic permission types (eg CRUD). This almost always leads to awkward compromises and often to violating the principle of least privilege, because each generic permission ends up granting access to a confusing smorgasbord of operations.

I'd recommend starting with a one-to-one mapping between permissions and exposed #API actions - "increaseTheFrobinator" or whatever. Then carefully aggregate those into more general permission classes if necessary, guided by user needs rather than technical neatness.

I've made SurillyaID available to the public! You can now use SurillyaID as an alternative / primary (whatever you want) login system using OIDC or OAuth 2!

Developer Portal: developer.surillya.com

Peertube Tutorial: video.surillya.com/w/fsbWVJU7E

YouTube tutorial: youtu.be/YQVn3aCgqLQ

#developer #php #oidc #openid #surillyaid #login #authorization #developers #webdev #html #website

A screenshot showing the SurillyaID developer dashboard

Fisheries Department grants authorization for port expansion in Contrecoeur, Que.
Fisheries and Oceans Canada has granted authorization to the Montreal Port Authority to expand a container port terminal northeast of the city in the habitat of an endangered fish species. 
#expansion #authorization #port #Contrecoeur #Que
cbc.ca/news/canada/montreal/au

Marcus Fihlon (McPringle)mcpringle_jugch@videos.ijug.eu
2025-12-26

Modern Identity Management in the era of Serverless and Microservices

videos.ijug.eu/w/ksXzydwQkYp68

Alvin Ashcraft 🐿️alvinashcraft@hachyderm.io
2025-12-17

RunAs Radio Show 1015 - Zero Trust in 2026 with Michele Bustamante and host Richard Campbell

runasradio.com/Shows/Show/1015

#podcast #devcommunity #security #ciso #authentication #authorization #zerotrust

2025-12-15

Tôi muốn có thư viện ủy quyền an toàn kiểu dữ liệu với ít cú pháp rườm rà, vì vậy tôi tự tạo ra **zap-studio/permit**: Quản lý logic ủy quyền tập trung, hỗ trợ TypeScript 100%, tích hợp Zod/Valibot/ArkType, dùng được trên Express, Fastify, Next.js và nhiều nền tảng khác. Giải pháp để giao diện sạch, hạn chế lỗi và dễ kiểm thử! #JavaScript #TypeScript #Authorization #DevTools #PhátTriểnPhầnMềm

reddit.com/r/SideProject/comme

Piotrek Jeremiczpiotrekjeremicz
2025-12-08

The time has come! 🕒

My new project is taking shape with , modules, and a stable core. is now part of a larger workspace.

Starting now, I'll share the progress of the first MVP: the layer. 🚀

2025-11-30

Interesting read about #authentication and #authorization in #localfirst #p2p software.

I still have a few more alternatives to review, but the library @localfirst/auth could be a good option.

herbcaudill.com/words/20240602

2025-09-24

RBACX — универсальный RBAC/ABAC-движок авторизации для Python

RBACX — авторизация без боли в Python-проектах Когда доступ «размазан» по вьюхам и миддлварам, ревью и тесты превращаются в квест - появляется мотивация все это унифицировать. Я написал RBACX — лёгкий движок, где правила описываются декларативно (JSON/YAML), а проверка прав — это один понятный вызов. В статье показываю, как собрать из него аккуратный PDP для микросервисов и монолитов. Я последние два года пишу бэкенд в стартапе MindUp — это мой первый пост на Хабре, и первая библиотека. Буду рад вопросам и критике. Если тема авторизации болит так же, как у меня, загляните!

habr.com/ru/articles/950080/

#python #rbacx #RBAC #ABAC #fastapi #authorization #django #flask #litestar #accesscontrol

Frontend Dogmafrontenddogma@mas.to
2025-09-01

An Illustrated Guide to OAuth, by (not on Mastodon or Bluesky):

ducktyped.org/p/an-illustrated

#guides #oauth #authorization

|7eter l-|. l3oling 🧰galtzo@ruby.social
2025-08-30
Inautiloinautilo
2025-08-26


An illustrated guide to OAuth · How delegated access works behind the scenes ilo.im/166dtf

_____

:rss: Qiita - 人気の記事qiita@rss-mstdn.studiofreesia.com
2025-08-16
Alvin Ashcraft 🐿️alvinashcraft@hachyderm.io
2025-07-30

MCP Gets OAuth: Understanding the New Authorization Specification | MCP Dev Days.

youtube.com/watch?v=EXxIeOfJsq

#mcp #ai #oauth #authorization #modelcontextprotocol #aiagents

Alvin Ashcraft 🐿️alvinashcraft@hachyderm.io
2025-07-18

OAuth 2.0 Access Tokens and the Principle of Least Privilege | by Andrea Chiarelli.

auth0.com/blog/oauth2-access-t

#authorization #oauth #auth0

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst