Identity
OIDC provider, SCIM, WebAuthn, tokens with closed scopes. A scope that is not held is not asked for: it does not appear.
DevKosher security is read in what the server refuses, not in what the screen hides.
OIDC provider, SCIM, WebAuthn, tokens with closed scopes. A scope that is not held is not asked for: it does not appear.
The BFF filters a view description before rendering it: a column, a filter or an action whose scope is not held does not appear in the response. An authorisation applied only on the surface is an absent authorisation.
The audit log is append-only and chained: a removed entry breaks the chain, and the break is visible.
Les modalités de signalement de vulnérabilité sont publiées avec la plateforme, avec un délai de réponse annoncé et tenu. [fr]