Blog
2 published articles
π
Developer Security
12
OAuth 2.0 PKCE for Browser and Mobile Apps: The Threat-Model-First Setup
Why PKCE matters for public clients, code verifier/challenge, state and nonce, token storage, and the flows you must not use in browser/mobile.
B
Blog-Ghar Editorialπ
Developer Security
14
GitHub Actions OIDC for Cloud Deployments: Reduce Long-Lived Secrets Step by Step
A least-privilege migration plan for replacing stored cloud keys with short-lived workload identity tokens.
B
Blog-Ghar Editorial