<div dir="ltr"><div class="gmail_default" style="font-family:verdana,sans-serif;font-size:small"><span style="font-family:Arial,Helvetica,sans-serif">if you are interested</span>: <a href="https://medium.com/@fabien.berteau/why-we-should-no-longer-use-bearer-tokens-to-protect-sensitive-single-page-applications-a7597c6c3097">https://medium.com/@fabien.berteau/why-we-should-no-longer-use-bearer-tokens-to-protect-sensitive-single-page-applications-a7597c6c3097</a></div><div class="gmail_default" style="font-family:verdana,sans-serif;font-size:small"><br></div><div><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><font color="#888888"><span><p dir="ltr" style="line-height:1.656;margin-left:4pt;margin-top:0pt;margin-bottom:0pt"><span style="font-size:11pt;font-family:Arial;color:rgb(0,0,0);background-color:transparent;vertical-align:baseline;white-space:pre-wrap"><span style="border:none;display:inline-block;overflow:hidden;width:267px;height:56px"><img src="https://lh5.googleusercontent.com/mLThoaiNugBlY4336DnmDiuIG7T4T71JCb3kLkYrOMcE-1nM3a1lA0fpE33NtqLXdQp8lUz4a4inFD0brKSjQaBudko0GGV3VfNTExNt3kX1_2QriimWy587sTrXfElf-Y435tWF" style="margin-left:0px;margin-top:0px" width="267" height="56"></span></span></p><br><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="font-size:10pt;font-family:Verdana;color:rgb(102,102,102);background-color:transparent;font-weight:700;vertical-align:baseline;white-space:pre-wrap">Fabien Berteau </span><span style="font-size:9.5pt;font-family:Verdana;color:rgb(61,133,198);background-color:transparent;font-weight:700;vertical-align:baseline;white-space:pre-wrap">|</span><span style="font-size:10pt;font-family:Verdana;color:rgb(102,102,102);background-color:transparent;font-weight:700;vertical-align:baseline;white-space:pre-wrap"> Security Architect</span></p><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="font-size:11pt;font-family:Verdana;color:rgb(102,102,102);background-color:transparent;vertical-align:baseline;white-space:pre-wrap">Bordeaux</span></p><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="font-size:9.5pt;font-family:Verdana;color:rgb(17,85,204);background-color:transparent;vertical-align:baseline;white-space:pre-wrap"><a href="mailto:aurelien.lajoie@manomano.com" target="_blank">fabien.berteau@manomano.com</a></span></p></span></font></div></div></div><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">Le jeu. 21 oct. 2021 à 15:28, Fabien BERTEAU <<a href="mailto:fabien.berteau@manomano.com">fabien.berteau@manomano.com</a>> a écrit :<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><div dir="ltr"><div class="gmail_default" style="font-family:verdana,sans-serif;font-size:small">I too am against the concept of SPA but after a long stint in the world of education where SAML reigns supreme, here I am in an online commerce company where many young people only know JavaScript, SPA, React, web and OIDC services. </div><div class="gmail_default" style="font-family:verdana,sans-serif;font-size:small">I have no choice but to adapt but we are coming to the limits of this technology and that's where I say to myself: why not SAML?<br><br>The main reason why I do not agree with the very principles of OIDC is that the access token is a bearer security. </div><div class="gmail_default" style="font-family:verdana,sans-serif;font-size:small">Anyone who captures it can use it as its rightful owner. And no OIDC protocol protects these tokens from an XSS-type attack. </div><div class="gmail_default" style="font-family:verdana,sans-serif;font-size:small">However, our hackers have assessed that the risk incurred by our company has become too great with this technology and forces us to no longer store these tokens in a context reachable by an XSS-type attack. </div><div class="gmail_default" style="font-family:verdana,sans-serif;font-size:small">If the session cookie is HTTP only and secure, then it is out of scope and should be automatically loaded by the browser when it is called via its XMLHTTPRequest interface.</div><div class="gmail_default" style="font-family:verdana,sans-serif;font-size:small"><br></div><div><div dir="ltr"><div dir="ltr"><font color="#888888"><span><p dir="ltr" style="line-height:1.656;margin-left:4pt;margin-top:0pt;margin-bottom:0pt"><span style="font-size:11pt;font-family:Arial;color:rgb(0,0,0);background-color:transparent;vertical-align:baseline;white-space:pre-wrap"><span style="border:none;display:inline-block;overflow:hidden;width:267px;height:56px"><img src="https://lh5.googleusercontent.com/mLThoaiNugBlY4336DnmDiuIG7T4T71JCb3kLkYrOMcE-1nM3a1lA0fpE33NtqLXdQp8lUz4a4inFD0brKSjQaBudko0GGV3VfNTExNt3kX1_2QriimWy587sTrXfElf-Y435tWF" style="margin-left: 0px; margin-top: 0px;" width="267" height="56"></span></span></p><br><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="font-size:10pt;font-family:Verdana;color:rgb(102,102,102);background-color:transparent;font-weight:700;vertical-align:baseline;white-space:pre-wrap">Fabien Berteau </span><span style="font-size:9.5pt;font-family:Verdana;color:rgb(61,133,198);background-color:transparent;font-weight:700;vertical-align:baseline;white-space:pre-wrap">|</span><span style="font-size:10pt;font-family:Verdana;color:rgb(102,102,102);background-color:transparent;font-weight:700;vertical-align:baseline;white-space:pre-wrap"> Security Architect</span></p><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="font-size:11pt;font-family:Verdana;color:rgb(102,102,102);background-color:transparent;vertical-align:baseline;white-space:pre-wrap">Bordeaux</span></p><p dir="ltr" style="line-height:1.38;margin-top:0pt;margin-bottom:0pt"><span style="font-size:9.5pt;font-family:Verdana;color:rgb(17,85,204);background-color:transparent;vertical-align:baseline;white-space:pre-wrap"><a href="mailto:aurelien.lajoie@manomano.com" target="_blank">fabien.berteau@manomano.com</a></span></p></span></font></div></div></div><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">Le jeu. 21 oct. 2021 à 15:18, Cantor, Scott <<a href="mailto:cantor.2@osu.edu" target="_blank">cantor.2@osu.edu</a>> a écrit :<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">On 10/21/21, 9:11 AM, "users on behalf of Fabien BERTEAU" <<a href="mailto:users-bounces@shibboleth.net" target="_blank">users-bounces@shibboleth.net</a> on behalf of <a href="mailto:fabien.berteau@manomano.com" target="_blank">fabien.berteau@manomano.com</a>> wrote:<br>
<br>
>    This answer scares me because we already use OIDC but we realize that it is not enough.<br>
<br>
I'm not saying it's secure, I haven't studied any of it. I got off this train a lot of stops back when it became clear I did not have a compatible worldview to deal with it.<br>
<br>
> To overcome this, we use a reverse proxy overlay (NextAuth) to make our OIDC authorization server believe<br>
> that we are still in Authorization Code flow. But this results in an overly complex system which I think could be<br>
> simplified with SAML. If you yourself are against the use of SAML in this increasingly widespread use case,<br>
> then I am afraid of us :)<br>
<br>
I'm not against the use of SAML if you think it's what you want, I'm simply against the concept of a SPA and I am not sorry or sad that people think SAML doesn't work well with them. To me that suggests we got it pretty right.<br>
<br>
In the end though, I'm not sure what the difference is between a code being accessible to javascript and making a session cookie accessible to it. Same thing, isn't it?<br>
<br>
-- Scott<br>
<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://shibboleth.atlassian.net/wiki/x/ZYEpPw" rel="noreferrer" target="_blank">https://shibboleth.atlassian.net/wiki/x/ZYEpPw</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>
</blockquote></div>