Open in app

Sign In

Write

Sign In

Mifraz Murthaja
Mifraz Murthaja

27 Followers

Home

About

Dec 8, 2022

The visibility of plain text credentials in the browser is not a vulnerability

Have you ever seen plain-text credentials in the browser? Do you think, it’s an application vulnerability? The direct answer would be, No. That’s how the protocol works and it’s the intended behavior of the browser. Well, let’s dig into the question, “WHY?” It’s not an application vulnerability, since it’s only visible in the particular user’s browser and…

4 min read

The visibility of plain text credentials in the browser is not a vulnerability
The visibility of plain text credentials in the browser is not a vulnerability

4 min read


Dec 1, 2022

The role of cookies in session management

Are you in a confusion about cookie vs session? Simply, the cookie is used to track the user information on the client side, whereas the session is used to track the user information on the server side. Since the HTTP protocol is stateless, implementing session management in a web application…

3 min read

The role of cookies in session management
The role of cookies in session management

3 min read


Apr 3, 2021

Testing FIDO in WSO2 Identity Server using Mobile Fingerprint

Let’s test the WSO2 Identity Server using the mobile phone, specifically FIDO. MFA using FIDO - WSO2 Identity Server Documentation  This section provides details on Fast IDentity Online (FIDO) and instructions on how to configure multi-factor…is.docs.wso2.com In the context of testing, it’s inevitable to access WSO2 IS using the mobile phone. Nevertheless, it involves several challenges such as, Cannot access WSO2 IS using localhost as we do on the PC.

Wso 2 Is

5 min read

Testing WSO2 Identity Server FIDO using Mobile Fingerprint
Testing WSO2 Identity Server FIDO using Mobile Fingerprint
Wso 2 Is

5 min read


Feb 9, 2021

Let the Countdown begin when the account is locked!

Customizing the login page to implement a countdown for the locked users in WSO2 Identity Server. Enabling the Account Locking due to Failed Login Attempts feature helps prevent brute-forcing for user credentials for an account. However, implementing a security feature always impacts the legit user’s user experience and is indispensable…

Wso 2

3 min read

Account Lock Countdown in WSO2 Identity Server
Account Lock Countdown in WSO2 Identity Server
Wso 2

3 min read


May 31, 2020

Implement SSO for Zendesk using WSO2 Identity Server

Implementing SSO for Zendesk Customer Support Ticket System using WSO2 Identity Server. Zendesk is one of the major support, sales, and customer engagement software that enables businesses to quickly implement and easily scales to meet changing needs. But as providing support is a part of your business, your organization might…

Wso 2

7 min read

Implement SSO for Zendesk using WSO2 Identity Server
Implement SSO for Zendesk using WSO2 Identity Server
Wso 2

7 min read


May 23, 2020

Implement SSO for Thinkific LMS using WSO2 Identity Server

Implementing SSO for Thinkific LMS using WSO2 Identity Server. Thinkific is a software platform that enables entrepreneurs to create, market, sell, and deliver their own online courses. Besides that, if you’re having multiple applications on your organization and if you want to implement a single point of authentication platform (Single…

Thinkific

8 min read

Integrate Thinkific LMS with WSO2 Identity Server
Integrate Thinkific LMS with WSO2 Identity Server
Thinkific

8 min read


May 22, 2020

JWT SSO with WSO2 Identity Server

An inbound authentication protocol to implement JWT based SSO for your application with WSO2 Identity Server. Before we dive into the topic, I hope you know the terms, JWT and SSO. You may aware of the protocols used to implement SSO on your application such as SAML and OpenID Connect…

Wso 2 Identity Server

7 min read

JWT SSO with WSO2 Identity Server
JWT SSO with WSO2 Identity Server
Wso 2 Identity Server

7 min read


Apr 30, 2020

WSO2 IS Custom Health Checker for Web App Endpoints

In the administration point of view, testing server health is an obligatory requirement. In the same context, WSO2 Identity Server provided built-in Carbon Health Check API which can be used to check the health of WSO2 Identity Server. There are three health checkers available by default, which are: Data sources…

Wso 2 Identity Server

3 min read

Wso 2 Identity Server

3 min read

Mifraz Murthaja

Mifraz Murthaja

27 Followers

Senior Software Engineer at WSO2

Following
  • Prabath Siriwardena

    Prabath Siriwardena

  • Lochana Edirisinghe

    Lochana Edirisinghe

  • Maneesha Indrachapa

    Maneesha Indrachapa

  • Ayesha Dissanayaka

    Ayesha Dissanayaka

  • Dehami Koswatte

    Dehami Koswatte

Help

Status

Writers

Blog

Careers

Privacy

Terms

About

Text to speech