1. X
  2. DevOps Rob
Log inSign up
DevOps Rob
6,778 posts
Image
user avatar
DevOps Rob
@devops_rob
1/2 of @keepinitsecure Podcast | Tech Hacker @HashiCorp | Game Player | linktr.ee/devopsrob | Tweets are my own views 🇬🇭
London, England
youtube.com/devopsrob
Joined February 2016
3,405
Following
2,540
Followers
RepliesRepliesMediaMedia

New to X?

Sign up now to get your own personalized timeline!

Create account

By signing up, you agree to the Terms of Service and Privacy Policy, including Cookie Use.

Terms·Privacy·Cookies·Accessibility·Ads Info·© 2026 X Corp.
Don't miss what's happening
People on X are the first to know.
Log inSign up
  • Pinned
    user avatar
    DevOps Rob
    @devops_rob
    Jan 1, 2023
    #VALORANT 2023 clips 🧵
    9.3K
  • user avatar
    DevOps Rob
    @devops_rob
    Apr 27
    Anyone else having trouble with the @digitalocean cloud control panel not loading properly? No side nav menu and a “Looks like something went wrong” message but status page says all is well. #ItIsNot
    Image
    204
  • user avatar
    DevOps Rob
    @devops_rob
    Jan 24, 2025
    @SheeenKelly happy bday. I logged into twitter just to send this. Hope you have a wonderful day. The Mrs sends her bday wishes too
    19
  • user avatar
    DevOps Rob
    @devops_rob
    Nov 20, 2024
    This is why I used Vault as an OIDC provider for my application. I have a write here for more implementation details hashicorp.com/blog/configuri…
    user avatar
    50Cal
    @Real50Cal_
    Nov 19, 2024
    Replying to @VoxelPrismatic and @forgebitz
    Handling your own user Authentication can be a lot of work, storing creds in the DB ,hashing and salting etc …with things like OIDC/OAuth2 you don’t have to store user login creds and handle Authentication , you can just rely on the “big” tech companies to take care of it .
    603
  • user avatar
    DevOps Rob
    @devops_rob
    Nov 20, 2024
    I literally just did this for the first time last week. I generate state and add it to the state param in the redirect url and also stored it in a redis. Then I do state validation on the callback function comparing the returned state to the one in redis, rejecting it if no match
    user avatar
    Sandrino Di Mattia
    @sandrinodm
    Nov 19, 2024
    Replying to @forgebitz
    Your code doesn’t seem to be performing any state validation, meaning you’re open to CSRF attacks
    862
  • See @devops_rob's full profile

    Sign up
    Log in
Advertisement
Advertisement