pknoth
Boruta server - a lightweight Identity and Access Management solution
Still an ongoing work but yet OpenID certified I have been writing a standalone version on top of boruta | Hex that includes:
- an OAuth 2.0/OpenID Connect certified authorization server
- an identity provider with configurable backends
- an administration interface
- a light gateway that enables authorization
The source code is available at GitHub - malach-it/boruta-server: Lightweight Identity and Access Management server, manage authentication and authorization up to decentralized identity · GitHub
I am looking for production use cases to integrate this first beta release. If you have any need for an identity and access management solution, drop me a note to discuss the needs for such an integration.
The documentation is still a work in progress, do not hesitate to reach out if you have questions about how it does work or what is possible to do with the server.
All kinds of feedback will be very welcome!
Thank you for reading me so far, hope to see you around.
Most Liked
pknoth
Hi again,
Few months ago, I recorded a loom presentation about the installation of the server. Here it is, with the hope it will help better understand how it works. Boruta - installation - 25 October 2022 | Loom
Cheers
pknoth
I am glad to say that this server is now also certified for the Config and Dynamic OP by the OpenID Foundation.
I released then version 0.2.0 with quite a lot of improvements:
- [gateway] introspected token forwarding to updatreams
- [identity] email templates edition
- [identity] configure, expose and edit user metadata
- [identity] user metadata configuration
- [gateway] static configuration
- [gateway] microgateways
- [identity] identity federation (login with button)
- [auth] better well-known openid configuration
- [auth] dynamic client registration
- [auth] client authentication methods configuration
- [auth] global signing key pairs
As a reminder,
I also plan to launch a documentation website to better understand how the server works, stay tuned.
With care,
pknoth
I just finished recording the series of demo videos of boruta:
- the installation - Boruta - installation - 25 October 2022 | Loom
- the OAuth clients - Boruta - oauth clients - 09 february 2023 | Loom
- the identity providers and the users - Boruta - idp, backends, and users - 16 April 2023 | Loom
- the (micro)gateway - Boruta · gateway - 6 May 2023 | Loom
- the monitoring - Boruta · monitoring - 31 May 2023 | Loom
Have a look, all feedback is welcome!
Thank you for listening to me (if you have).
Cheers
Last Post!
pknoth
The version 0.4.0 is out.
This release contains (as stated in the changelog):
- [ssi] Configurable verifiable credentials issuance with oid4vci implementation
- [ssi] Siopv2 same device implementation
- [auth] Demonstration proof of possession implementation
- [auth] Pushed Authorization Request implementation
- [infra] Server ip address bindings configuration via environment variables
- [infra]Infrastructure as Code with static file configuration
- [admin] Admin ui improvements
- [auth] Better identity federation
- [identity] Webauthn integration
- [infra] Remote IP logging
This brings boruta to the new era of the Self-Sovereign Identity with certified verifiable credentials issuance abilities. Cannot wait the implementation of verification with oid4vp!
Have a great morning/evening/afternoon wherever you are.
Popular in Announcing
Other popular topics
Categories:
Sub Categories:
Forums
Popular Tags
- #ecto
- #liveview
- #troubleshooting
- #learning-elixir
- #deployment
- #library
- #erlang
- #testing
- #genserver
- #mix
- #absinthe
- #remote-other
- #otp
- #plug
- #how-to-question
- #macros
- #postgres
- #channels
- #elixirconf
- #exunit
- #discussion
- #code-sync
- #javascript
- #podcasts
- #onsite
- #dialyzer
- #docker
- #authentication
- #umbrella
- #full-time-contract
- #podcasts-by-brainlid
- #ecto-query
- #elixir-ls
- #phoenix_html
- #iex
- #blog-post
- #graphql
- #genstage
- #ai
- #websockets
- #supervisor
- #elixirconf-us
- #advent-of-code
- #distillery
- #processes
- #forms
- #api
- #metaprogramming
- #hex
- #security









