RedmineのネイティブOAuth2でAIエージェントに安全にRedmineを操作させる - Qiita

TL; DR Redmine 6.1 のネイティブ OAuth2 + ゲートウェイで client_secret を集約し、CLI ツールがトークンを隠蔽することで、API キー不要・スコープ制限付き・AI コンテキストへのトークン漏洩なしで Redmine を操作させ...

Qiita

The IETF just published a framework for AI agent identity. AIMS composes SPIFFE, WIMSE, and OAuth 2.0 into an 8-layer model that replaces static API keys with proper workload identity. 53% of MCP servers still use API keys — this changes that.

https://iamdevbox.com/posts/ietf-aims-ai-agent-identity-management-system-spiffe-oauth/?utm_source=mastodon&utm_medium=social&utm_campaign=blog_post

#AIAgentSecurity #OAuth #SPIFFE #IAM #IdentitySecurity

Any fediverse developers with too much free time on their hands interested in helping me figure out why, when logging in with a Friendica account, I get an "Unprocessable Entity" error?

https://github.com/stefanbohacek/auth-server

#fediverse #oauth #friendica #fedidevs #nodejs #opensource

Every time someone on your team connects an AI tool to their work account, a new OAuth identity gets created in your environment.

It doesn't expire when the tool stops being used. It doesn't get caught by standard offboarding. It just persists, holding access nobody's monitoring.

In most orgs, NHIs like these outnumber human ones. Most were never inventoried.

Visibility is step one. Auth Sentry Monitor is free:

gethumming.io/Monitor/

#IdentitySecurity #ITDR #OAuth #CyberSecurity

BIツールの進化先?! DBを業務分析用のMCPサーバにしてBIを次世代にする - Qiita

はじめに AI時代におけるBIツールとは何かを考えていく中で、「AIにDBを繋げば、ダッシュボードを作り込まなくても誰でも手軽にデータ分析ができるのでは?」 と思い立ち、 DBに直接接続するMCPサーバを構築してみました。 DB+MCPといえば、ローカルで起動するMCPサ...

Qiita
Grafanaの管理者って6種類あんねん【Cognito連携】 - Qiita

はじめに 以前の記事で作成したGrafana環境で、ブラウザ上のGUIからプラグインを追加しようとしたところ、以下のように権限がないと怒られてしまいました。 以前の記事はこちら。 この記事に書いた設定で構築した通り、Grafanaの「管理者」にマッピングしているC...

Qiita

@researchbuzz Good luck!

I see some OAuth labeled bugs in the repo: https://github.com/goauthentik/authentik/issues?q=is%3Aissue%20is%3Aopen%20oauth%20label%3Abug

I'm adding some tags, just in case #OAuth #Patreon #FediHelp ⬆️⬆️⬆️

So i am thinking out loud:
In the past i wanted to create an identity system, where the users could create sets of personal data like phone number(s), email adress(es), bank account(s) and physical adress(es) etc.
Then they could share grants, which are like an access control for a specific subset of those.
Could this be realised with private claims from OAuth?
Example in the next posts.
#OAuth #IdentityManagement

I hate it when people think OAuth is the only way to do things. Fine, it you are a web app running in a browser and using a third party service where your users don't want to let you see their credentials.

But, for a first party CLI app, perhaps making me copy & paste a four line URL, then log in on a different machine and copy back a long token string isn't the best option.

Also, don't put a 15 second time limit on an operation like that. #AI #Claude #FAIL #OAuth

foojay – a place for friends of OpenJDK

foojay is the place for all OpenJDK Update Release Information. Learn More.

foojay