Safeguard
Tag

oauth

Safeguard articles tagged "oauth" — guides, analysis, and best practices for software supply chain and application security.

25 articles

Application Security

Account Linking by Email Match Trusts a Claim, Not a Verification

Continue with Google links to the matching existing account by email address. That is correct when the identity provider genuinely verified the email. Some providers make verification optional, and not every system checks which claim it is reading.

Sep 18, 20266 min read
Compliance

Every SaaS Tool Nobody Approved Still Has Access

Someone signed up with a company card, connected it with broad OAuth scopes, used it for a quarter, and stopped. The subscription lapsed. The integration did not. Adopting a tool costs nothing; removing one requires someone to remember it exists.

Sep 18, 20265 min read
Application Security

A Deep Link Is an Unauthenticated Entry Point Into Your App

Anything can send one: a web page, a QR code, a message, another app on the device. With a custom scheme there is not even a guarantee the link reaches your app rather than someone else's.

Sep 18, 20265 min read
Application Security

Every Connected App Holds a Credential Nobody Reviews

A user clicks approve in about four seconds and an application you did not write holds a token to their data, refreshing itself indefinitely. In most products nobody can list them afterwards.

Sep 18, 20266 min read
Infrastructure Security

The Subdomain You Forgot Is Someone Else's Now

A CNAME outlives the vendor account it pointed at, the platform frees the hostname, and anyone can claim it. The damage is rarely the defaced page: it is parent-domain cookies, OAuth redirects and a CSP that trusts subdomains.

Sep 17, 20266 min read
Security

Device Code Phishing Rose 15x. Checking the URL Does Not Help.

Device code phishing sends victims to a genuine Microsoft page to enter a genuine code. There is no fake domain and no credential to steal. Training built on spotting bad URLs has nothing to use.

Aug 9, 20266 min read
AI Security

How to authorize and scope permissions for autonomous AI ...

A practical, step-by-step guide to AI agent authorization: scoping permissions, using OAuth for machine identities, and verifying least-privilege boundaries hold in production.

Aug 5, 20268 min read
Supply Chain Attacks

Lessons from the CircleCI 2023 secrets breach

A stolen session cookie bypassed 2FA and let attackers read secrets from live memory. CircleCI's own timeline shows what fast rotation actually requires.

Jul 15, 20267 min read
Application Security

Where should your SPA store auth tokens?

OWASP has warned against localStorage tokens for years, yet it remains the default in countless SPA tutorials — one XSS bug is all it takes to exfiltrate every session.

Jul 10, 20266 min read
AI Security

Securing MCP Servers for AI Agents

Five CVEs in 2025 alone trace MCP tool compromise back to one root cause: unsanitized strings piped into exec(). Here's how to expose and consume MCP safely.

Jul 9, 20267 min read
Security Guides

OAuth 2.0 Security Best Practices (2026)

OAuth 2.0 is safe when you follow the current security BCP and dangerous when you follow a decade-old tutorial. Here is what RFC 9700 requires in 2026: PKCE everywhere, exact redirect matching, and sender-constrained tokens.

Jul 7, 20266 min read
Security Guides

Single-Page Application Security: Tokens, XSS, and the Public Bundle

In an SPA, one XSS is game over and your entire bundle is public. Here's how token storage, CSP, OAuth PKCE, and CORS decide whether your SPA holds.

Jul 7, 20265 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.