Tag: Security
14 posts
-
OAuth 2.0 & JWT authentication — token login and refresh flows
JWT and OAuth 2.0: sessions vs tokens, authorization code flow, PKCE, token endpoint, scopes and consent, Node.js/Passport, Google and Kakao.
-
Authentication with Passport.js: Local Login, Google and GitHub OAuth, JWT and Session Stores
Adding authentication to Node.js with Passport.js: local username/password login, protected routes, Google and GitHub OAuth, JWT strategy, combining strategies, and production session stores.
-
Securing Express with Helmet: CSP, HSTS, Frame Options and the Headers That Matter
Hardening Express apps with Helmet: what each security header does, configuring Content Security Policy and HSTS, clickjacking and MIME-sniffing protection, and referrer policy.
-
Managing Environment Variables with dotenv: Multi-Environment Files, Defaults, Validation and Secrets
Managing environment variables in Node.js with dotenv: loading .env files, ES modules, custom paths, multi-environment setups, defaults, validation, and keeping secrets out of git.
-
CORS in Express: Allowed Origins, Credentials, Preflight Requests and Dynamic Origins
Configuring CORS in Node.js and Express: why browsers block requests, allowing specific or dynamic origins, cookies and credentials, preflight requests, and per-route settings.
-
Password Hashing with bcrypt in Node.js: Cost Factors, the 72-Byte Limit and Thread Pool Pitfalls
Hashing passwords with bcrypt in Node.js: choosing a cost factor, the 72-byte input limit, thread pool saturation, reset tokens, and the login and ORM-hook pitfalls that quietly weaken it.
-
JWT Authentication in Node.js: Refresh Token Rotation, HttpOnly Cookies and Revocation
Implement JWT authentication in Node.js and Next.js: short-lived access tokens, rotating refresh tokens with reuse detection, HttpOnly cookie storage, CSRF, Redis revocation, and when sessions are the better choice.
-
Docker Multi-Stage Builds: Smaller Images, Layer Caching, BuildKit Cache Mounts and Secret Leaks
Shrink Docker images from over 1GB to a fraction of that with multi-stage builds. Layer caching, cache invalidation, and secret leakage explained.
-
Docker Security in Production: Non-Root Images, Secrets, Capabilities and the Mistakes That Expose Hosts
Harden Docker containers where it matters: non-root images that Kubernetes accepts, build secrets that do not leak into layers, dropping capabilities, why -p bypasses your firewall, and why mounting docker.sock is root on the host.
-
Node.js Authentication and Security: JWT, bcrypt, and Sessions
Secure Node.js APIs: bcrypt password hashing, JWT access tokens with pinned algorithms, rotated and hashed refresh tokens, where to store tokens in the browser, sessions with a shared store, Passport OAuth, and the defaults that make auth code insecure.
-
Hardening SSH on Linux Servers: sshd_config, Key Authentication, Agent Forwarding and Jump Hosts
How SSH key exchange and host verification work, key-only authentication, sshd_config hardening that actually takes effect, agent forwarding risks, port forwarding, known_hosts, and ProxyJump bastions with OpenSSH.
-
C++ SSL/TLS with OpenSSL and Asio: Handshake, Certificates and Common Errors [#30-2]
Add TLS to a C++ server with OpenSSL and Asio: the handshake, self-signed and Let's Encrypt certificates, mTLS, and fixes for hostname and chain errors.
-
C++ Buffer Overflows: Causes, Safe APIs, and Security Impact
Buffer overflows in C and C++: strcpy, memcpy, stack and heap corruption, ASan, strncpy vs string, bounds checks, and secure coding patterns.
-
API Rate Limiting: Fixed Window, Sliding Log and Token Bucket, and Making Them Atomic in Redis
How fixed window, sliding log, and token bucket rate limiters actually behave, how to make them atomic in Redis, and the proxy, clock, and retry pitfalls that break them in production.