Web Hacking Members Only

Authentication Mechanisms

Every authentication scheme the modern web speaks — HTTP Basic, Digest, form-based, OAuth 2.0, OpenID Connect, SAML 2.0. The wire format of each, when to use which, the famous attacks (XML signature wrapping, redirect_uri tampering, credential stuffing), and a battle-tested decision matrix.

Related Articles