Securing Web Apps with Okta: Moving from Implicit to Authorization Code Flow
Stop leaking tokens in your URLs. Learn how to implement the OIDC Authorization Code Flow with Okta to secure user identity and verify JWTs using discovery endpoints.
ReadMeFeed / Community knowledge
Real questions. Useful conversations. Find the people who know your stack.
Stop leaking tokens in your URLs. Learn how to implement the OIDC Authorization Code Flow with Okta to secure user identity and verify JWTs using discovery endpoints.
Learn how to configure Google Cloud Pub/Sub push subscriptions with OIDC tokens so that external webhooks receive authenticated events without managing custom token services.
In a Kubeflow environment utilizing Istio for authentication, the auth-proxy validates OIDC tokens at the request level. While Kubernetes RBAC manages permissions based on OIDC groups, there is a discrepancy between the identity provider's state and the active Istio session. When a user is deactivated or their credentials are rotated in the OIDC provider, th
Credential Lifecycle Management Argo CD implements least-privilege access by mapping external identity provider groups to internal roles via RBAC policies. For OIDC-based authentication, the API server validates the exp claim on every request, resulting in an HTTP 401 response once the token expires, which necessitates a client-side re-authentication flow. S
Argo CD manages permissions through the argocd-rbac-cm ConfigMap, where the policy.default setting determines the baseline permissions for users who do not have an explicitly assigned role. When integrating with external OIDC providers, there is a potential for ambiguity regarding how the system handles authenticated users who belong to no defined groups or
Implementing least-privilege access in Terraform often involves using short-lived credentials via OIDC or IAM roles to minimize the risk of long-lived secret leakage. While this architecture reduces the blast radius of a compromise, it introduces dependencies on the credential lifecycle during long-running operations. There is uncertainty regarding how diffe