Moving Supabase users to Open Source Cloud without resetting their passwords
How to import Supabase users and their existing bcrypt password hashes into Keycloak on Open Source Cloud, so nobody has to reset a password.
Tag archive
How to import Supabase users and their existing bcrypt password hashes into Keycloak on Open Source Cloud, so nobody has to reset a password.
GitHub has extended npm trusted publishing to cover dist-tag changes under short-lived OIDC credentials, but the new permission ships off by default on every configuration.
Add OpenID Connect login to an Undertow application with pac4j: configure sessions, protect routes, and handle callbacks and logout.
Enterprise SSO is a federation of trust, not one shared login session. SAML or OIDC carries identity proof, while each application still owns its session and authorization.

Introduction In my previous posts, I briefly mentioned the important topic of zero static...

Introduction In my last post, I briefly mentioned the important topic of zero static...

What I learned wiring several apps to one Zitadel and brokering out to a customer's Keycloak: two very different APIs, a PKCE toggle that does nothing, and a logout that cannot federate.

Introduction In one of my previous posts, I described how I tested new possibilities for...
A CNCF blog post argues that the 'confidential' OIDC client most on-prem clusters use for kubectl is a shared static credential in disguise, and that a public client with PKCE is the honest fit for a CLI that lives on every operator's laptop.

We ship one small API client in several languages. The code is nearly identical each time: five...

Introduction Every static credential starts out reasonable. A pipeline needs to SSH into...
This article is in German. It covers OIDC Workload Identity Federation for CI/CD pipelines (AWS, GCP,...