SShortSingh.
Back to feed

Step-up MFA, attenuation, and what's honestly not done

0
·13 views

Repo: darkedges/pf12.3-biscuit-datalog-tokens We've covered why a hybrid works, the token generator plugin, and the Terraform plus end-to-end test. Part 3 ended with alice holding orders:write and still getting a 403. This part unlocks that write, narrows the token in a few ways, and then says plainly what doesn't work yet. orders-api's policy has three rules: allow if scope("orders:read"), operation("read"); allow if scope("orders:write"), operation("write"), amr("mfa") trusting authority, ed25519/ ; deny if true; A write needs the scope and an amr("mfa") fact. It also has to be a fact the se

Read the full story at DEV Community

This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)

Log in to join the discussion and vote.

Log in

Related stories

0
ProgrammingDEV Community ·

SayLess

This is a submission for the Hacktoberfest Weekend Challenge: Build for a Friend This is a submission for the Hacktoberfest Weekend Challenge: Build for a Friend. I built SayLess, a private writing assistant for difficult conversations. Sometimes you know what you want to say, but finding the right words is hard. SayLess helps by turning a message into three short reply options: Soft, Natural, and Direct. You can also choose what you want to communicate, such as apologizing, explaining, saying no, or setting a boundary.

0
ProgrammingDEV Community ·

Bitget $387.5M Hack Analysis: Zero-Day Exploit, Admin Credential Theft, and THORChain Laundering

In late September 2026, the cryptocurrency industry witnessed one of its most sophisticated exchange breaches to date. Bitget, a major global digital asset platform, suffered a massive security incident resulting in the loss of approximately $387.5 million. Unlike typical hot wallet key extractions, this attack leveraged a zero-day vulnerability, compromised administrative credentials, and highly efficient cross-chain laundering techniques. The incident not only highlights the evolving tactics of state-aligned threat actors but also underscores the critical role of artificial intelligence in m