caddy-security
goth
Our great sponsors
caddy-security | goth | |
---|---|---|
17 | 7 | |
1,234 | 4,969 | |
- | - | |
8.1 | 6.2 | |
20 days ago | 5 days ago | |
Go | Go | |
Apache License 2.0 | MIT License |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
caddy-security
- Caddy-Security: Security App and Plugin for Caddy
-
Security flaws in an SSO plugin for Caddy
There is no "refusal" as far as I can tell. The issues were reported [1] in September 2023 (as was this blog post) and the simplest one has been fixed (insecure random seed). I'm not aware of any public statements from the plugin maintainers, and there is no hostility in the issue comments.
[1]: https://github.com/greenpau/caddy-security/issues?q=is%3Aiss...
> September 18, 2023: The disclosure blog post was released and issues were filed with the original project repository.
I don't see those issues listed in the GitHub project issue tracker https://github.com/greenpau/caddy-security/issues. Have they been deleted?
-
Web authentication for reverse proxy
Check out https://github.com/greenpau/caddy-security
-
What 3rd party auth provider would you guys recommend to use with Caddy on Windows, and are there any tutorials or documentation?
There a pretty comprehensive auth plugin for Caddy. It can do local authentication with a session cookie, which should work with your IPTV apps. If your app can show a login form, it's super easy, but if I remember correctly you can also authenticate with basic auth and store the session in a cookie (this is mostly used to carry over the authentication to a different subdomain).
-
Q: I need help with securing my selfhosted services
I use Caddy + Caddy Security, set up OAuth, and also only expose services over IPv6. It's not extra security, but it's less logs to deal with because nobody is scanning IPv6 address ranges, and there are less IPv6 capable hosts who are compromised.
- Authentication in Go? Best practices
-
Web server with content upload and authentication
Not sure if this fits your bill, but have a look at Caddy web server and its available authentification methods or even more with a plugin
-
Hiding Public IP
Also look at github.com/greenpau/caddy-security to enable MFA for Caddy.
-
Guacamole + LetsEncrypt (Nginx/Træfik) + VPN ? (x-post r/selfhosted)
- Guacamole docker connects to Debian VNC Desktop - Caddy docker offers HTTPS proxy with Guacamole and the Caddy Security plug in for Auth with TOTP
goth
-
How to build Auth in 2023 with go?
Also really easy to implement as there are libraries that do all the heavy lifting for you (https://github.com/markbates/goth is a great starting place IMHO)
-
Why use a 'global' anonymous function instead of a named one?
In the package 'markbates/goth' that provides a client implementation of OAuth 2.0, the authors have defined the function CompleteUserAuth at the package level like this:
- Authentication in Go? Best practices
-
Single sign on with LinkedIn
You can use oauth2. Just take e.g. a look at the dex documentation dex. Dex is not a library but a standalone federated oidc provider. Highly recommended. For libraries take a look at goth.
- Simple web app, how to do auth?
-
The impossible case of pitching rust in a web dev shop
For the kind of websites I prefer to build -- server side rendered with HTMX/Alpine for the extra niceness -- Rust I think could be a very good fit. The main downside for my personal projects is the ecosystem. E.g., a good standard way to handle CSRF tokens, standardised oauth2 implementations (like https://github.com/markbates/goth in Go), things like that. I found myself having to write a lot of code that just exists in the Go ecosystem. The main downside for a business is that it's going to make it harder to hire, since Rust genuinely requires more skill. Yes, developers will make mistakes in Go, as it's far too easy to do things like access shared memory in dangerous ways. But on the flip side, it's a lot easier for them to deliver a feature. In a choice between shipping a feature that is buggy in hard to detect ways, vs not being able to deliver at all because you can't get developers, I think it's better to ship.
- เขียน Go ต่อ Oauth ทุกค่าย
What are some alternatives?
caddy-auth-portal - Authentication Plugin for Caddy v2 implementing Form-Based, Basic, Local, LDAP, OpenID Connect, OAuth 2.0 (Github, Google, Facebook, Okta, etc.), SAML Authentication. MFA with App Authenticators and Yubico.
oauth2 - Go OAuth2
scim-for-keycloak - a third party module that extends keycloak by SCIM functionality
go-oauth2-server - A standalone, specification-compliant, OAuth2 server written in Golang.
caddy-maxmind-geolocation - Caddy v2 module to filter requests based on source IP geolocation
authboss - The boss of http auth.
SuperTokens Community - Open source alternative to Auth0 / Firebase Auth / AWS Cognito
jwt-go - ARCHIVE - Golang implementation of JSON Web Tokens (JWT). This project is now maintained at:
webauthn - WebAuthn (FIDO2) server library written in Go
gologin - Go login handlers for authentication providers (OAuth1, OAuth2)
Keycloak - Open Source Identity and Access Management For Modern Applications and Services
jwt-auth - This package provides json web token (jwt) middleware for goLang http servers