{"repo":"GrottoPress/shield","free":true,"listed":false,"github":"https://github.com/GrottoPress/shield","clone":"git clone https://github.com/GrottoPress/shield.git","description":"Comprehensive security for Lucky framework","language":"Crystal","stars":57,"topics":["lucky-framework","authentication","security","crystal","oauth2"],"license":"MIT","category":"auth-billing-email","readme_excerpt":"Shield Shield is a comprehensive Identity & Access Management solution for Lucky framework. It features robust authentication and authorization, including user registrations, logins and logouts, password resets and more. Shield is secure by default, and exploits defence-in-depth strategies, including the option to pin an authentication session to the IP address that started it -- the session is invalidated if the IP address changes. User IDs are never saved in session. Instead, each authentication gets a unique ID and token, which is saved in session, and checked against their corresponding salted SHA-256 digests in the database. When a user changes their password, Shield logs out the user on all devices (except the current one), to ensure that an attacker no longer has access to a previously compromised account. Shield supports API authentication, with regular passwords or with user-generated bearer tokens. In addition, Shield comes with tools to build your own OAuth 2.0 authorization server. Shield is designed to be resilient against critical application vulnerabilities, including brute force, user enumeration, denial of service and timing attacks. On top of these, Shield offers seamless integration with your application. For the most part, include a bunch of module s in the appropriate class es, and you are good to go! Design principles - #### Zero knowledge Shield maintains no knowledge of any secrets, and stores them such that they are irrecoverable, either by the applic","default_branch":null,"files":null,"tree":[],"storefront":"/r/GrottoPress","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/GrottoPress/shield/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}