oauth
Safeguard articles tagged "oauth" — guides, analysis, and best practices for software supply chain and application security.
25 articles
Account Linking by Email Match Trusts a Claim, Not a Verification
Continue with Google links to the matching existing account by email address. That is correct when the identity provider genuinely verified the email. Some providers make verification optional, and not every system checks which claim it is reading.
Every SaaS Tool Nobody Approved Still Has Access
Someone signed up with a company card, connected it with broad OAuth scopes, used it for a quarter, and stopped. The subscription lapsed. The integration did not. Adopting a tool costs nothing; removing one requires someone to remember it exists.
A Deep Link Is an Unauthenticated Entry Point Into Your App
Anything can send one: a web page, a QR code, a message, another app on the device. With a custom scheme there is not even a guarantee the link reaches your app rather than someone else's.
Every Connected App Holds a Credential Nobody Reviews
A user clicks approve in about four seconds and an application you did not write holds a token to their data, refreshing itself indefinitely. In most products nobody can list them afterwards.
The Subdomain You Forgot Is Someone Else's Now
A CNAME outlives the vendor account it pointed at, the platform frees the hostname, and anyone can claim it. The damage is rarely the defaced page: it is parent-domain cookies, OAuth redirects and a CSP that trusts subdomains.
Device Code Phishing Rose 15x. Checking the URL Does Not Help.
Device code phishing sends victims to a genuine Microsoft page to enter a genuine code. There is no fake domain and no credential to steal. Training built on spotting bad URLs has nothing to use.
How to authorize and scope permissions for autonomous AI ...
A practical, step-by-step guide to AI agent authorization: scoping permissions, using OAuth for machine identities, and verifying least-privilege boundaries hold in production.
Lessons from the CircleCI 2023 secrets breach
A stolen session cookie bypassed 2FA and let attackers read secrets from live memory. CircleCI's own timeline shows what fast rotation actually requires.
Where should your SPA store auth tokens?
OWASP has warned against localStorage tokens for years, yet it remains the default in countless SPA tutorials — one XSS bug is all it takes to exfiltrate every session.
Securing MCP Servers for AI Agents
Five CVEs in 2025 alone trace MCP tool compromise back to one root cause: unsanitized strings piped into exec(). Here's how to expose and consume MCP safely.
OAuth 2.0 Security Best Practices (2026)
OAuth 2.0 is safe when you follow the current security BCP and dangerous when you follow a decade-old tutorial. Here is what RFC 9700 requires in 2026: PKCE everywhere, exact redirect matching, and sender-constrained tokens.
Single-Page Application Security: Tokens, XSS, and the Public Bundle
In an SPA, one XSS is game over and your entire bundle is public. Here's how token storage, CSP, OAuth PKCE, and CORS decide whether your SPA holds.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.