{"repo":"vhscom/private-landing","free":true,"listed":false,"github":"https://github.com/vhscom/private-landing","clone":"git clone https://github.com/vhscom/private-landing.git","description":"🔐 Learn authentication by building it right. An extensible, standards-compliant reference implementation for Cloudflare Workers with Hono, Turso, PBKDF2, and JWT dual-token sessions.","language":"TypeScript","stars":80,"topics":["pbkdf2","authentication","cloudflare-worker","educational","hono","jwt","nist","owasp","reference-implementation","security"],"license":"Apache-2.0","category":"auth-billing-email","readme_excerpt":"Private Landing Learn authentication by building it right. Live Demo · Threat Model · Auth Flows · ADRs Demo note: The login endpoint is protected by adaptive PoW challenges — repeated failures return increasing proof-of-work difficulty. Cache-backed rate limiting is implemented and tested but not currently enabled on the live demo; flip createCacheClient in app.ts to activate it. --- A from-scratch authentication reference implementation for Cloudflare Workers — PBKDF2 password hashing, JWT dual-token sessions, constant-time comparison, sliding expiration, and a removable observability plugin — all wired together with Hono, Turso (with optional Valkey/Redis caching), and strict TypeScript. Every design choice traces back to a standard: NIST SP 800-63B for credentials, NIST SP 800-132 for key derivation, OWASP ASVS for verification, and RFC 8725 for JWT best practices. Shipping a product? Use Better Auth instead — it covers OAuth, passkeys, MFA, rate limiting, and more out of the box with an active plugin ecosystem. This repo exists to teach you how auth works, not to replace a production library. Why this repo - Read the code, not just the docs — every security property (timing-safe rejection, session-linked revocation, algorithm pinning) is implemented and tested, not just described - NIST + OWASP + RFC references throughout — learn the why behind each decision - 630+ tests including attack-vector suites (token tampering, algorithm confusion, unicode edge cases) - Observabi","default_branch":null,"files":null,"tree":[],"storefront":"/r/vhscom","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/vhscom/private-landing/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}