photog.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
A place for your photos and banter. Photog first is our motto Please refer to the site rules before posting.

Administered by:

Server stats:

247
active users

#oauth

0 posts0 participants0 posts today
Alvin Ashcraft 🐿️<p>MCP Gets OAuth: Understanding the New Authorization Specification | MCP Dev Days.</p><p><a href="https://www.youtube.com/watch?v=EXxIeOfJsqA" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">youtube.com/watch?v=EXxIeOfJsq</span><span class="invisible">A</span></a> </p><p><a href="https://hachyderm.io/tags/mcp" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>mcp</span></a> <a href="https://hachyderm.io/tags/ai" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ai</span></a> <a href="https://hachyderm.io/tags/oauth" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>oauth</span></a> <a href="https://hachyderm.io/tags/authorization" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>authorization</span></a> <a href="https://hachyderm.io/tags/modelcontextprotocol" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>modelcontextprotocol</span></a> <a href="https://hachyderm.io/tags/aiagents" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>aiagents</span></a></p>
Third spruce tree on the left<p>When you get the option to `Sign in with Google/Microsoft/Facebook` you're really using <a href="https://mas.to/tags/OAuth" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OAuth</span></a>. Aside from those platforms knowing what you're doing everywhere all the time, there are compelling reasons for both 3rd party services and users. (not many, but a few). </p><p>But if you DO link your <a href="https://mas.to/tags/Microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Microsoft</span></a> / <a href="https://mas.to/tags/Google" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Google</span></a> / <a href="https://mas.to/tags/Facebook" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Facebook</span></a> account to some other service, there's never anyway to UNLINK it, and that's just lazy cowardly product management, $0.02. Oh and its deliberate.</p><p><a href="https://awadwatt.com/tezoatlipoca/poor-software-product-management-chronicles-e-auth-i-auth-oauth-fuck-off" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">awadwatt.com/tezoatlipoca/poor</span><span class="invisible">-software-product-management-chronicles-e-auth-i-auth-oauth-fuck-off</span></a></p>
Wladimir Mufty<p>Setting up a sector-wide <a href="https://social.edu.nl/tags/PeerTube" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>PeerTube</span></a> pilot instance on behalf of Dutch higher ed &amp; research using <a href="https://social.edu.nl/tags/SSO" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SSO</span></a> via <a href="https://social.edu.nl/tags/SAML" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SAML</span></a>, so no local usernames/passwords…</p><p>Anyone with experience uploading videos using the <a href="https://social.edu.nl/tags/REST" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>REST</span></a> <a href="https://social.edu.nl/tags/API" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>API</span></a> for system integration purposes? No classic <a href="https://social.edu.nl/tags/OAuth" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OAuth</span></a> flow here… or is it possible?!</p><p>💚➡️ <a href="https://social.edu.nl/tags/Framasoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Framasoft</span></a> <a href="https://social.edu.nl/tags/Fediverse" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Fediverse</span></a> <a href="https://social.edu.nl/tags/OpenSource" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenSource</span></a> <a href="https://social.edu.nl/tags/Education" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Education</span></a> <a href="https://social.edu.nl/tags/Science" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Science</span></a> <a href="https://social.edu.nl/tags/askfedi" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>askfedi</span></a></p><p>👩🏽‍🎓 <a href="https://video.edu.nl/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="">video.edu.nl/</span><span class="invisible"></span></a></p>
Alvin Ashcraft 🐿️<p>OAuth 2.0 Access Tokens and the Principle of Least Privilege | by Andrea Chiarelli.</p><p><a href="https://auth0.com/blog/oauth2-access-tokens-and-principle-of-least-privilege/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">auth0.com/blog/oauth2-access-t</span><span class="invisible">okens-and-principle-of-least-privilege/</span></a> </p><p><a href="https://hachyderm.io/tags/authorization" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>authorization</span></a> <a href="https://hachyderm.io/tags/oauth" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>oauth</span></a> <a href="https://hachyderm.io/tags/auth0" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>auth0</span></a></p>
OpenStreetMap Ops Team<p>If you manage a web application that uses OpenStreetMap.org authentication or independently use the OpenStreetMap-website code, please see our recent security notice: <a href="https://operations.osmfoundation.org/2025/07/11/security-notice.html" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">operations.osmfoundation.org/2</span><span class="invisible">025/07/11/security-notice.html</span></a> <a href="https://en.osm.town/tags/OpenStreetMap" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OpenStreetMap</span></a> <a href="https://en.osm.town/tags/OSM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OSM</span></a> <a href="https://en.osm.town/tags/Security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Security</span></a> <a href="https://en.osm.town/tags/OAuth" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OAuth</span></a></p>
Alvin Ashcraft 🐿️<p>OAuth in the MCP C# SDK: Simple, Secure, Standard | by Den Delimarsky.</p><p><a href="https://den.dev/blog/mcp-csharp-sdk-authorization/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">den.dev/blog/mcp-csharp-sdk-au</span><span class="invisible">thorization/</span></a></p><p><a href="https://hachyderm.io/tags/ai" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ai</span></a> <a href="https://hachyderm.io/tags/oauth" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>oauth</span></a> <a href="https://hachyderm.io/tags/csharp" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>csharp</span></a> <a href="https://hachyderm.io/tags/dotnet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>dotnet</span></a> <a href="https://hachyderm.io/tags/auth" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>auth</span></a> <a href="https://hachyderm.io/tags/mcp" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>mcp</span></a> <a href="https://hachyderm.io/tags/modelcontextprotocol" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>modelcontextprotocol</span></a></p>
Yaal Coop<p>Demain c'est l'été, il est temps de faire le point sur le mécénat et les contributions à des logiciels libres commis par l'équipe de Yaal Coop ces 3 derniers mois ! Au menu, beaucoup de choses autour d'outils <a href="https://toot.aquilenet.fr/tags/oidc" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>oidc</span></a> et <a href="https://toot.aquilenet.fr/tags/oauth" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>oauth</span></a> en <a href="https://toot.aquilenet.fr/tags/python" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>python</span></a><br><a href="https://yaal.coop/blog/dernieres-contributions-logiciels-libres-printemps-2025" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">yaal.coop/blog/dernieres-contr</span><span class="invisible">ibutions-logiciels-libres-printemps-2025</span></a></p>
Schenkl | 🏳️‍🌈🦄<p>Kaum instlliert eins die xdg-utils in den Container, kann <a href="https://chaos.social/tags/JOSM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>JOSM</span></a> auch den <a href="https://chaos.social/tags/OAuth" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OAuth</span></a> an den <a href="https://chaos.social/tags/Browser" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Browser</span></a> werfen.</p><p>In der <a href="https://chaos.social/tags/Java" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Java</span></a> Fehlermeldung steht natürlich nichtsdergleichen^^</p><p><a href="https://chaos.social/tags/Docker" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Docker</span></a></p>
Hollo :hollo:<p><a class="mention hashtag" rel="nofollow noopener" href="https://hollo.social/tags/Hollo" target="_blank">#<span>Hollo</span></a> 0.6.0 is coming soon!</p><p>We're putting the finishing touches on our biggest security and feature update yet. Here's what's coming:</p><p><strong>Enhanced <a class="mention hashtag" rel="nofollow noopener" href="https://hollo.social/tags/OAuth" target="_blank">#<span>OAuth</span></a> <a class="mention hashtag" rel="nofollow noopener" href="https://hollo.social/tags/security" target="_blank">#<span>security</span></a></strong></p><ul> <li>RFC 8414 (OAuth metadata discovery)</li><li>RFC 7636 (<a class="mention hashtag" rel="nofollow noopener" href="https://hollo.social/tags/PKCE" target="_blank">#<span>PKCE</span></a> support)</li><li>Improved authorization flows following RFC 9700 best practices</li> </ul><p><strong>New features</strong></p><ul> <li>Extended character limit (4K → 10K)</li><li>Code syntax highlighting</li><li>Customizable profile themes</li><li>EXIF metadata stripping for privacy</li> </ul><p><strong>Important notes for update</strong></p><ul> <li>Node.js 24+ required</li><li>Updated environment variables for asset storage</li><li>Stronger <code>SECRET_KEY</code> requirements (44+ chars)</li> </ul> <p>Special thanks to <a translate="no" class="h-card u-url mention" href="https://hachyderm.io/@thisismissem" rel="nofollow noopener" target="_blank">@<span>thisismissem</span></a> for the extensive OAuth improvements that help keep the <a class="mention hashtag" rel="nofollow noopener" href="https://hollo.social/tags/fediverse" target="_blank">#<span>fediverse</span></a> secure and compatible! 🙏</p><p>Full changelog and upgrade guide coming with the release.</p><p><a class="mention hashtag" rel="nofollow noopener" href="https://hollo.social/tags/ActivityPub" target="_blank">#<span>ActivityPub</span></a></p>
udo m. rader ☕ 🇪🇺 🇺🇦 🐧<p>I'm not easily swearing, but how can I put this: sending infra emails from a data center to addresses managed by <a href="https://sigmoid.social/tags/Microsoft" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Microsoft</span></a> 365 is crazy. MS dislikes <a href="https://sigmoid.social/tags/SMTP" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SMTP</span></a> AUTH, ok, and so begins the <a href="https://sigmoid.social/tags/OAuth" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OAuth</span></a> journey to get the <a href="https://sigmoid.social/tags/postfix" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>postfix</span></a> mail relay to embrace OAuth</p><p>The best idea so far is to write a script that acts as a proxy between postfix and MS, sending emails via the MS <a href="https://sigmoid.social/tags/GraphAPI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GraphAPI</span></a>. Undoubtedly much more secure and, just as undoubtedly, absolutely no vendor lock-in for something as simple as SMTP ... WTF!!</p>
Joe Steinbring :thisisfine:<p>I got n8n working with LinkedIn, Mastodon, etc. Can I get it to work with Fitbit? :blobcatthink: </p><p><a href="https://toot.works/tags/Homelab" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Homelab</span></a> <a href="https://toot.works/tags/n8n" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>n8n</span></a> <a href="https://toot.works/tags/OAuth" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OAuth</span></a></p>
Aaron PareckiIn two weeks I'll be speaking at the MCP Dev Summit in San Francisco! It's going to be a great day packed with back to back sessions. <br> <br>In less than a year, the MCP project has quickly reshaped how developers are building AI agents. My talk, "Intro to OAuth for MCP Servers", will cover the basics of the new MCP authorization protocol and set the stage for building secure MCP servers. <br> <br><a href="https://mcpdevsummit.ai/#agenda" rel="nofollow noopener" target="_blank"><span class="">https://</span>mcpdevsummit.ai/#agenda</a>
Maarten Balliauw<p>Just did a big rewrite of a docs page on dynamic identity providers in Duende <a href="https://mastodon.online/tags/identityserver" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>identityserver</span></a>.</p><p>That was fun to dive in, and makes me appreciate the thought put in to designing both <a href="https://mastodon.online/tags/aspnetcore" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>aspnetcore</span></a> and IdentityServer itself.</p><p><a href="https://docs.duendesoftware.com/identityserver/ui/login/dynamicproviders/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">docs.duendesoftware.com/identi</span><span class="invisible">tyserver/ui/login/dynamicproviders/</span></a></p><p><a href="https://mastodon.online/tags/dotnet" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>dotnet</span></a> <a href="https://mastodon.online/tags/security" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>security</span></a> <a href="https://mastodon.online/tags/oauth" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>oauth</span></a></p><p>(also big thanks to <span class="h-card" translate="no"><a href="https://mastodon.social/@khalidabuhakmeh" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>khalidabuhakmeh</span></a></span> for the fantastic preview images on new docs pages)</p>
Efani<p>⚠️ Phishers have found a clever way to spoof Google — and their emails pass all security checks.</p><p>A new DKIM replay phishing attack abuses Google’s own OAuth infrastructure to send fake messages that look 100% legitimate, including passing DKIM authentication.</p><p>What happened:<br>- A phishing email was sent from “no-reply@google.com” <br>- It appeared in the user’s inbox alongside real Google security alerts <br>- The message linked to a fake support portal hosted on sites[dot]google[dot]com — a Google-owned domain <br>- The attacker used Google OAuth to trigger a real security alert to their inbox, then forwarded it to victims </p><p>Why this matters:<br>- DKIM only verifies the headers, not the envelope — allowing this spoof to work <br>- The phishing site was nearly indistinguishable from Google’s actual login portal <br>- Because the message was signed by Google and hosted on a Google domain, it bypassed most users’ suspicions <br>- Similar tricks have been used with PayPal and other platforms, raising broader concerns </p><p>Google has since acknowledged the issue and is working on a fix. But this attack is a reminder:</p><p>Even the most secure-looking emails can be fraudulent. <br>Even Google-signed emails can be weaponized.</p><p>🛡️ At <span class="h-card" translate="no"><a href="https://infosec.exchange/@Efani" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>Efani</span></a></span>, we advocate for layered defense — because no one layer is ever enough.</p><p><a href="https://infosec.exchange/tags/Cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Cybersecurity</span></a> <a href="https://infosec.exchange/tags/Phishing" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Phishing</span></a> <a href="https://infosec.exchange/tags/Google" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Google</span></a> <a href="https://infosec.exchange/tags/OAuth" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OAuth</span></a> <a href="https://infosec.exchange/tags/DKIM" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DKIM</span></a> <a href="https://infosec.exchange/tags/EmailSecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EmailSecurity</span></a> <a href="https://infosec.exchange/tags/EfaniSecure" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>EfaniSecure</span></a> <a href="https://infosec.exchange/tags/ThreatIntel" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ThreatIntel</span></a></p>
teufelswerk<p>Cyberkriminelle nutzen aktuell gefälschte OAuth-Anwendungen, die sich als bekannte Dienste wie Adobe Acrobat, Adobe Drive oder DocuSign ausgeben. Ziel dieser Angriffe ist es, sich Zugriff auf Microsoft-365-Konten zu erschleichen. Im Beitrag erfährst du auch, wie du dich vor solchen Angriffen schützen kannst.</p><p><a href="https://teufelswerk.net/achtung-vor-boesartigen-adobe-und-docusign-oauth-apps-so-schuetzt-du-dein-microsoft-365-konto/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">teufelswerk.net/achtung-vor-bo</span><span class="invisible">esartigen-adobe-und-docusign-oauth-apps-so-schuetzt-du-dein-microsoft-365-konto/</span></a></p><p><a href="https://social.tchncs.de/tags/phishing" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>phishing</span></a> <a href="https://social.tchncs.de/tags/scam" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>scam</span></a> <a href="https://social.tchncs.de/tags/cybersecurity" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>cybersecurity</span></a> <a href="https://social.tchncs.de/tags/OAuth" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OAuth</span></a> <a href="https://social.tchncs.de/tags/Adobe" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Adobe</span></a> <a href="https://social.tchncs.de/tags/DocuSign" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>DocuSign</span></a> <a href="https://social.tchncs.de/tags/microsoft365" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>microsoft365</span></a> <a href="https://social.tchncs.de/tags/office365" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>office365</span></a></p>
Matthew Turland<p>If you had to explain <a href="https://phpc.social/tags/OAuth2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OAuth2</span></a> to a relatively new SWE who only had a bit of experience interacting with public APIs from a frontend UI, are there any specific beginner-friendly online resources you'd recommend to them?</p><p><a href="https://phpc.social/tags/OAuth" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OAuth</span></a> <a href="https://phpc.social/tags/Authentication" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Authentication</span></a> <a href="https://phpc.social/tags/SoftwareEngineering" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SoftwareEngineering</span></a> <a href="https://phpc.social/tags/SoftwareDevelopment" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>SoftwareDevelopment</span></a> <a href="https://phpc.social/tags/Education" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Education</span></a></p>
shearichard<p>I'm presenting at the Wellington Python New Zealand meetup on Thursday evening, so if you're in town come along and cheer. </p><p>The subject is integrating <a href="https://mastodon.nz/tags/OAuth" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OAuth</span></a> into a <a href="https://mastodon.nz/tags/Django" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Django</span></a> project : what OAuth is and how it works; a good approach to integrating it into a Django project ; and what benefits it brings.</p><p>Although the talk with be Django-centric I hope those attending will be able to contribute their experience of using OAuth in <a href="https://mastodon.nz/tags/Flask" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Flask</span></a>, <a href="https://mastodon.nz/tags/FastAPI" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>FastAPI</span></a> etc.</p><p>Sign up is here : <a href="https://www.meetup.com/pythonnz-wellington/events/304242570/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://www.</span><span class="ellipsis">meetup.com/pythonnz-wellington</span><span class="invisible">/events/304242570/</span></a></p>
C.<p><a href="https://mindly.social/tags/Fedi" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Fedi</span></a>, looking for people with experience in <a href="https://mindly.social/tags/accessible" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>accessible</span></a> software.</p><p>I have a friend with serious vision issues. Not blind, but can't easily read text that isn't 6+ inches high, and his vision is degrading. He is looking for a way to deal with email -- he's a writer -- because he says Gmail is now a nightmare to use even with a screen reader.</p><p>Preferred solution would be a mail program / <a href="https://mindly.social/tags/MUA" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MUA</span></a> that runs on Windows and supports <a href="https://mindly.social/tags/OAUTH" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>OAUTH</span></a> authentication, so he can continue to use his Gmail address.</p><p>What's the MUA with the best <a href="https://mindly.social/tags/accessibility" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>accessibility</span></a> on Windows? Thunderbird brags about its support for screen readers and assistive technologies, so I had him try it, and he says it's almost as bad as Gmail - flashing colours, animating controls. I haven't personally touched Thunderbird in many years, so it was a surprise to me.</p><p>I use a text/console mail flow that relies on a local MTA, so nothing I use is of any use in this.</p><p>Thanks, appreciate any pointers.</p><p><a href="https://mindly.social/tags/mail" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>mail</span></a> <a href="https://mindly.social/tags/MailProgram" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>MailProgram</span></a> <a href="https://mindly.social/tags/GMail" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>GMail</span></a> <a href="https://mindly.social/tags/AssistiveTechnology" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>AssistiveTechnology</span></a> <a href="https://mindly.social/tags/Windows" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>Windows</span></a> <a href="https://mindly.social/tags/blind" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>blind</span></a> <a href="https://mindly.social/tags/vision" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>vision</span></a> <a href="https://mindly.social/tags/software" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>software</span></a> <a href="https://mindly.social/tags/disability" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>disability</span></a></p>
Aaron PareckiAt long last, the OAuth working group has finished the Best Current Practice for OAuth 2.0 Security and it was just published as RFC9700! This has been a long time in the works, and I'm very thankful to everyone who has helped out with it over the years! <br> <br><a href="https://www.rfc-editor.org/rfc/rfc9700.html" rel="nofollow noopener" target="_blank"><span class="">https://</span>www.rfc-editor.org/rfc/rfc9700.html</a> <br> <br>This is one of the major inputs to OAuth 2.1, so I'm also very excited to be able to move that forward this year as well!
Francis Augusto 🇳🇴/🇧🇷/:bahia:<p>A little rant about e-mail authentication: </p><p><a href="https://francisaugusto.com/2025/Email-quo-vadis-or-where-is-oidc-for-everyone/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">francisaugusto.com/2025/Email-</span><span class="invisible">quo-vadis-or-where-is-oidc-for-everyone/</span></a></p><p><span class="h-card" translate="no"><a href="https://io.mwl.io/@mwl" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>mwl</span></a></span> I'd love your comment on this!</p><p><a href="https://mastodon.babb.no/tags/email" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>email</span></a> <a href="https://mastodon.babb.no/tags/oauth" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>oauth</span></a> <a href="https://mastodon.babb.no/tags/oauth2" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>oauth2</span></a> <a href="https://mastodon.babb.no/tags/thunderbird" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>thunderbird</span></a></p>