Home / Companies / FusionAuth / Blog / April 2022

April 2022 Summaries

6 posts from FusionAuth

Filter
Month: Year:
Post Summaries Back to Blog
Discord is a popular platform used by various communities to form connections around shared interests. Using Discord as an SSO (Single Sign-On) identity provider can simplify the login process for users, allowing them to log in with their existing Discord credentials instead of creating multiple accounts. FusionAuth is a complete authentication and identity management platform that enables developers to quickly implement complex standards like OAuth, OpenID Connect, and SAML while building out additional login features. To set up an integration between Discord and FusionAuth, one needs to register a new application in the Discord Developer Portal, create a FusionAuth instance, configure the Discord Identity Provider, and enable it for the desired application. The final step involves creating an API key for the sample application to complete the setup. This tutorial demonstrates how to integrate Discord with FusionAuth using OAuth 2.0, allowing users to log in to various applications using their existing Discord credentials.
Apr 25, 2022 1,743 words in the original blog post.
FusionAuth, a developer-focused authentication and authorization platform, has received its SOC 2 Type 2 certification, demonstrating its commitment to security and adherence to industry-accepted auditing standards. The company was able to achieve this certification early in its lifecycle due to its focus on governance, risk, and compliance practices since inception. As a result, FusionAuth is now better equipped to support customers with robust security features such as OAuth, OpenID Connect, and SAML, which can be easily integrated into products built by developers. With its API-first approach and continually innovating features, FusionAuth aims to provide developers with control, flexibility, and ease of use in building essential user security without adding risk or complexity.
Apr 21, 2022 375 words in the original blog post.
FusionAuth version 1.36, released in April 2022, introduces several new features and enhancements, including SCIM 2 support, a Nintendo Online Identity Provider, and a new webhook for user identity provider linking events. SCIM 2 allows for standardized identity management across systems, enhancing user provisioning and synchronization with third-party SCIM-compliant backends. The addition of Nintendo Online as an identity provider enables users to log in via their Nintendo accounts, available to Enterprise and Essentials license holders. The new webhook feature empowers developers to trigger actions when users link or unlink identity providers, facilitating advanced analytics and customized functionality. Additional improvements include easier loading of custom password plugins, better handling of OAuth2 Password Grant MFA methods, and optimized system resource usage for higher login volumes. For more details, users are encouraged to review the release notes and upgrade their FusionAuth instances accordingly.
Apr 15, 2022 675 words in the original blog post.
The FusionAuth team has completed a rigorous audit process and earned SOC2 Type II certification for their entire organization, including the FusionAuth product. This certification demonstrates strict security and process controls, indicating a high level of maturity and security expertise in managing software partners. The achievement signifies FusionAuth's strong commitment to security, with confidential audit reports available upon request for contracted customers. The community can rest assured that SOC2 Type II certification reflects FusionAuth's readiness and awareness in protecting sensitive data.
Apr 14, 2022 193 words in the original blog post.
The recent announcement of CVE-2022-22965, a remote code execution vulnerability in Spring MVC or Spring WebFlux applications running on JDK 9+, has raised concerns among users. FusionAuth is not affected by this vulnerability as it uses a different MVC framework, Prime, and therefore cannot be compromised. However, security is important to FusionAuth, which takes various measures to ensure the security of its customers' applications, including a responsible disclosure program, regular penetration tests, and security disclosures in release notes.
Apr 05, 2022 224 words in the original blog post.
FusionAuth has announced BioTech, a new technology that enhances user security by utilizing bodily fluids as an additional factor of authentication. This method aims to make MFA more convenient and user-friendly, eliminating the need for devices or apps. Users can provide any bodily fluid, such as saliva, sweat, or tears, during login, which is then analyzed using a patented algorithm to authenticate them. The technology has undergone extensive testing, including user experience trials, and has shown promising results in terms of speed and accuracy. However, some security experts have raised concerns about the potential for exploitation by hackers and the need for protection of sensitive biometric data. Despite these criticisms, FusionAuth remains confident in the benefits of BioTech, calling it a "game-changer" in user authentication.
Apr 01, 2022 599 words in the original blog post.