Padosoft Auth Hardening

Use this skill when building or reviewing anything to do with who a user is and how long they stay that way — login, registration, password reset or change, email change, invitations, sessions, API tokens, second factor, logout, remember-me, a captcha on a form. Also when the user reports credential stuffing, an account enumeration finding, a session that never expires, a password change that did not log other devices out, a lockout that never fires, or asks what a new application needs before it opens to the public. It gives the control, the reason it is shaped that way, and the ways each one is commonly present but ineffective. Do not use it for authorisation and ownership (padosoft-tenant-isolation) or for the whole security posture (padosoft-security-baseline).

padosoft Updated

File contents

padosoft/skills/tree/main/skills/padosoft-auth-hardening commit cc6f53ea85

Frequently asked questions

npx skillmds@latest add padosoft/padosoft-auth-hardening