Authentication as a Microservice: Portable Customer Identity Management - Brian Pontarelli
3,127 views · Published 27 November 2018 · 37:47 · Indexed 30 September 2026
Channel: OWASP Foundation · 2018 · Science & Technology
Authentication is a core piece of many applications but it has traditionally been handled in a monolithic manner. Foreign keys to the user table and join tables for roles and permissions is the most common mechanism that applications use to manage user data. Moving to microservices means that applications now need to decouple authentication, user management, and user data. To accomplish this, a portable identity model is required. In this session, we will discuss the advantages of a microservice architecture, as well as the most common pitfalls including increased network chatter and various security issues. I’ll cover the basics of authentication and authorization as a microservice and JWT revocation. The goal is to allow developers to primarily focus on code and move away from infrastructure concerns. Speaker Brian Pontarelli CEO, Inversoft Brian Pontarelli is founder and CEO of Inversoft, a Denver-based provider of platform technologies built to help companies manage, moderate and engage their customers. These technologies include Passport, a modern identity and user management API that provides login, registration - Managed by the official OWASP Media Project https://www.owasp.org/index.php/OWASP_Media_Project
More from this channel
-
45:50
Revenge of the Geeks: Hacking Fantasy Sports Sites - Dan Kuykendall
-
35:56
HTML5 JS Security - maty siman
-
46:05
Next Generation Red Teaming - Robert Wood
-
17:39
detecting and defending against state actor surveillance: robert r
-
50:12
OWASP Global Webinar - OWASP HIVE Project - Welcome to the Grid
-
50:42
OWASP Global Webinar - Initiatives OWASP Projects
-
2:45:16
OWASP Board June 27, 2014 - part 2 (With Quorum)
-
42:16
Alvaro Muoz - Automatic Detection of Inadequate Authorization Checks in Web Applications