I wrote about how DPoP eliminates the "finders keepers" vulnerability of Bearer tokens. The article covers implementation with Keycloak and Quarkus, walks through replay attack and method/URL mismatch scenarios, and includes a ready-to-run repo. https://foojay.io/today/dpop-what-it-is-how-it-works-and-why-bearer-tokens-arent-enough/
Author and trainer, Java Geek
| GITHUB | https://github.com/hakdogan |
| POSTS ON MEDIUM | https://medium.com/@hakdogan |
| POSTS ON DZONE | https://dzone.com/users/1161493/hakdogan.html |
| POSTS ON FOOJAY.IO | https://foojay.io/today/author/huseyin-akdogan/ |
