Dominick Baier's Avatar

Dominick Baier

@leastprivilege.com.bsky.social

Advisor at Duende Software - @duendesoftware.com

267 Followers  |  30 Following  |  63 Posts  |  Joined: 10.11.2024  |  1.9365

Latest posts by leastprivilege.com on Bluesky

Preview
Duende Software - Identity and Access Management for .NET We help companies using .NET to build identity and access control solutions for modern applications.

How to test your #IdentityServer?

In this post, we demonstrate how to setup and run automated tests with your favorite test framework. #mstest #xunit #nunit #dotnet #security

duende.link/a4rs979

06.08.2025 16:19 β€” πŸ‘ 3    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0

Next video from our Identity & Access Control workshop: OpenID Connect

We cover tokens, scopes, the #aspnetcore OpenID Connect handler, the userinfo endpoint, token management, refresh tokens, and more.

youtube.com/watch?v=c41R...

#identityserver #aspnetcore #oauth2 #openidconnect #dotnet

04.08.2025 13:00 β€” πŸ‘ 0    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Post image

Building with #Blazor? πŸ‘·β€β™€οΈ

The BFF Security Framework offers built-in support to unify authentication state management across various rendering modes (Server, WASM, Auto) to secure API access from your app.

docs.duendesoftware.com/bff/fundamen...

#dotnet #security

04.08.2025 15:04 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

I heard your schwing is toight like a toiger

31.07.2025 06:03 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Preview
Duende Software - Identity and Access Management for .NET We help companies using .NET to build identity and access control solutions for modern applications.

Fresh post on external providers in #aspnetcore

We cover initial setup, the connection between external and cookie authentication, and discusses why alternatives might be better for production apps.

duende.link/q24tubs #security #identity #dotnet

28.07.2025 12:59 β€” πŸ‘ 1    πŸ” 5    πŸ’¬ 0    πŸ“Œ 0
Preview
Duende Software - Identity and Access Management for .NET We help companies using .NET to build identity and access control solutions for modern applications.

How to test your #IdentityServer?

In this post, we'll show how to setup and run automated tests with your favorite test framework. #mstest #xunit #nunit #dotnet #security

duende.link/a4rs979

25.07.2025 08:01 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
Duende Software - Identity and Access Management for .NET We help companies using .NET to build identity and access control solutions for modern applications.

How to test your #IdentityServer?

In this post, we'll show how to setup and run automated tests with your favorite test framework. #mstest #xunit #nunit #dotnet #security

duende.link/a4rs979

22.07.2025 13:01 β€” πŸ‘ 1    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Preview
DuckDuckGo Can Now Filter Out AI Images From Search Results Finally.

petapixel.com/2025/07/21/d...

21.07.2025 18:46 β€” πŸ‘ 0    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0
Video thumbnail

Think you're safe online? OAuth 2.0 in the browser could let attackers steal your access tokens and use them for as long as they are valid, acting on the user's behalf 😱

Interview with @philippederyck.bsky.social: youtu.be/urS9wstmN2U

#dotnet #security #bff #oauth2

18.07.2025 08:10 β€” πŸ‘ 0    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Preview
Duende Software - Identity and Access Management for .NET We help companies using .NET to build identity and access control solutions for modern applications.

What's In the Duende Software Toolkit? πŸ€”

πŸ’‘ Beyond #IdentityServer, discover solutions like the BFF Security Framework, Access Token Management, and IdentityModel. Plus, Duende Templates, a demo server, and extensive documentation. #dotnet #security

duende.link/2b87kja

15.07.2025 13:18 β€” πŸ‘ 2    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Copilot is pointing out that a post is future-dated and then randomly picking a date from 2 years ago.

Copilot is pointing out that a post is future-dated and then randomly picking a date from 2 years ago.

Tried GitHub Copilot code review, and it doesn’t understand the concept of future-dating blog posts. Worse, it suggests a random-ass date. This stuff sucks.

15.07.2025 15:09 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Preview
Duende Software - Identity and Access Management for .NET We help companies using .NET to build identity and access control solutions for modern applications.

Duende is committed to open source and values contributors. We are now sponsoring Astro and Starlight, the static site generator that powers our docs.

More details about Astro and why we are sponsoring on our blog: duende.link/astr055 #dotnet #astro #identity

14.07.2025 12:31 β€” πŸ‘ 4    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Post image

Supercharge your proxy needs! 🦸

Integrate with #YARP for advanced routing, load balancing, etc., while getting BFF's automatic token management and CSRF protection for proxied APIs.

Here's how to add it to your Backend for Frontend: docs.duendesoftware.com/bff/fundamen... #dotnet #security

09.07.2025 08:30 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Take the chance to attend my full three day workshop on ASP.NET Core Authentication/Authorization, OpenID Connect, OAuth 2.0 and Duende IdentityServer.

I'm hosting it online in August and an in person in Stockholm in September.

Early bird pricing until the end of July!

Will you be there?

09.07.2025 08:32 β€” πŸ‘ 1    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Post image

A Step Up challenge ensures critical actions are verified through additional scrutiny. You can handle this in client apps, but how do you communicate a step-up is needed from the API side? Let's see how to implement this in #aspnetcore

duende.link/318qkjl #dotnet #security

08.07.2025 13:45 β€” πŸ‘ 3    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Preview
What's your experience with User Management in .NET? Β· DuendeSoftware Β· Discussion #225 Here at Duende Software, we're exploring the landscape of user management in the .NET ecosystem. With the evolution of application architectures and security requirements, we're curious to understa...

Interesting question by @damian.social - What are you using for user management in #aspnetcore? #dotnet

github.com/orgs/DuendeS...

12.06.2025 04:48 β€” πŸ‘ 1    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
Preview
New release: IdentityServer 7.3.0 Release Candidate 1 Β· DuendeSoftware Β· Discussion #256 Great news today! The Duende IdentityServer 7.3.0 Release Candidate 1 has been published on NuGet! Release notes Upgrade guide IdentityServer 7.3 is a significant release that includes: FAPI 2.0 pr...

IdentityServer 7.3.0 Release Candidate 1 is out! It brings FAPI 2.0 profile certification, JWT response from the introspection endpoint, diagnostics data, OpenTelemetry updates, and more!

duende.link/is73rc1 #dotnet #security

07.07.2025 13:30 β€” πŸ‘ 2    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Preview
New release: IdentityServer 7.3.0 Release Candidate 1 Β· DuendeSoftware Β· Discussion #256 Great news today! The Duende IdentityServer 7.3.0 Release Candidate 1 has been published on NuGet! Release notes Upgrade guide IdentityServer 7.3 is a significant release that includes: FAPI 2.0 pr...

Check out the freshly deployed IdentityServer 7.3.0 Release Candidate 1. It brings FAPI 2.0 profile certification, JWT response from the introspection endpoint, diagnostics data, OpenTelemetry updates, and more!

duende.link/is73rc1 #dotnet #security

03.07.2025 08:01 β€” πŸ‘ 2    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0

To quote @hadihariri.com β€žfor number of visitors smaller than 1β€œ

03.07.2025 18:57 β€” πŸ‘ 1    πŸ” 0    πŸ’¬ 0    πŸ“Œ 0

Blazor is the Visual SourceSafe of the web. "Hey other visitor let me know when I can have a websocket OK?"

03.07.2025 12:43 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 1    πŸ“Œ 0
Preview
Duende Software Docs Get started building your .NET applications with IdentityServer, Backend-for-Frontend (BFF) and our open-source tools.

Duende is committed to open source and values contributors. We are now sponsoring Astro and Starlight, the static site generator that powers our docs.

More details about Astro and why we are sponsoring on our blog: duende.link/astr055 #dotnet #astro #identity

03.07.2025 15:31 β€” πŸ‘ 12    πŸ” 6    πŸ’¬ 0    πŸ“Œ 1
Post image

Add an extra layer of security to critical user actions! πŸ›‘οΈ

Learn how to implement Step Up challenges in your #aspnetcore apps with Duende #IdentityServer to enhance user verification and re-confirm identity for some activities.

duende.link/qthej2r

#dotnet #security #oidc

01.07.2025 13:00 β€” πŸ‘ 1    πŸ” 3    πŸ’¬ 0    πŸ“Œ 0
Post image

Remote APIs? Let the BFF handle it! 🀝

Your frontend calls the BFF using its session cookie. The BFF securely swaps this for an access token and proxies the call - the browser never sees the access token! πŸ™ˆ

Learn more: docs.duendesoftware.com/bff/fundamen... #dotnet #security

01.07.2025 17:31 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

Stop CSRF cold! πŸš”

Duende's BFF requires a simple custom header on authenticated API requests. This standard check and SameSite cookies provide strong protection against Cross-Site Request Forgery.

Learn how: docs.duendesoftware.com/bff/fundamen... #dotnet #security

02.07.2025 16:11 β€” πŸ‘ 2    πŸ” 2    πŸ’¬ 0    πŸ“Œ 0
AutoMapper and MediatR Commercial Editions Launch Today Today I'm excited to announce the official launch and release of the commercial editions of AutoMapper and MediatR. Both of these libraries have moved under their new corporate owner (me), Lucky Penny...

It's been a ton of work getting here but today I'm excited to announce the official commercial launch of AutoMapper and MediatR! More details here: www.jimmybogard.com/automapper-a... WHEW

02.07.2025 15:01 β€” πŸ‘ 58    πŸ” 26    πŸ’¬ 13    πŸ“Œ 2

Take the chance to attend my full three day workshop on ASP.NET Core Authentication/Authorization, OpenID Connect, OAuth 2.0 and Duende IdentityServer.

I'm hosting it in August and an in person version in Stockholm in September.

Early bird pricing until end of July!

Will you be there?

30.06.2025 06:42 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

Secure user sessions with robust cookies! πŸͺ

The Backend for Frontend (BFF) framework uses the #aspnetcore handler for HttpOnly, Secure, SameSite cookies, with strong session protection. Server-side sessions offer even more control.

docs.duendesoftware.com/bff/fundamen... #dotnet #security

27.06.2025 11:02 β€” πŸ‘ 1    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

IdentityServer4 has multiple security vulnerabilities, bugs, and outdated documentation, and it doesn't support newer .NET versions.

We're offering a free 30-minute Upgrade Assessment call to help plan your upgrade to Duende IdentityServer. #dotnet

duendesoftware.com/upgrade-iden...

26.06.2025 13:31 β€” πŸ‘ 0    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0

Awesome!!

24.06.2025 12:26 β€” πŸ‘ 6    πŸ” 1    πŸ’¬ 0    πŸ“Œ 0
Post image

The #dotnet 8.0.17 upgrade fixed validation of forwarded headers and proxy server configuration in load balanced scenarios.

Great! Or not πŸ€”
This patch may affect your #aspnetcore app. 😱

Check our blog post for background and fix: duende.link/0mgnet8

24.06.2025 13:01 β€” πŸ‘ 2    πŸ” 4    πŸ’¬ 0    πŸ“Œ 0

@leastprivilege.com is following 20 prominent accounts