Engineering SAML, OAuth 2.0, and OpenID Connect
- About this book
Introduction
Chapter 1: Identity, Authentication, and Authorization: The Foundations
- Principals, Identities, and Accounts
- Authentication versus Verification versus Identification
- Authorization and the Confused Deputy Problem
- Sessions and Their Invariants
- The Trust Boundary and What You Can Rely On
- From Single Systems to Federation
Chapter 2: The Web’s Authentication Heritage
- HTTP Basic and Digest Authentication
- Browser Cookies and Session Management
- Same-Origin Policy and Cross-Origin Constraints
- Forms-Based Authentication and Its Flaws
- The Need for Single Sign-On
- Early Enterprise SSO Attempts (Kerberos, LDAP, RADIUS)
Chapter 3: Federation and the Trust Model
- What Federation Means and Why It Exists
- Identity Providers and Service Providers
- Centralized versus Distributed Trust
- Assertions, Tokens, and the Statement Problem
- Metadata and Dynamic Trust
- The Role of Humans: Consent and Delegation
Chapter 4: HTTP, the Browser, and the Attack Surface
- The HTTP Redirect and State Transfer
- Cookie Scoping, SameSite, Secure, and HttpOnly
- Cross-Origin Requests and CORS
- Post Messages and Client-Side Communication
- The Browser as a Hostile Environment
- Logging, HSTS, and Transport Security
Chapter 5: SAML 2.0: Architecture and Concepts
- SAML’s Origins in Shibboleth and Liberty Alliance
- The SAML Vocabulary: Principals, Assertions, and Artifacts
- Identity Providers and Service Providers in SAML
- Bindings: HTTP-Redirect, HTTP-POST, and HTTP-Artifact
- Security Requirements: Signatures, Encryption, and Timestamps
- The SAML Processing Model
Chapter 6: SAML 2.0: Protocol Flows and Message Formats
- The Authentication Request (AuthnRequest)
- The Authentication Response and Asserted Claims
- Complete Protocol Trace: SP-Initiated SSO
- Complete Protocol Trace: IdP-Initiated SSO
- Single Logout (SLO) Flow
- Artifact Binding and Resolution
Chapter 7: XML Security for SAML
- XML Signature (XMLDSig): Enveloped, Enveloping, Detached
- Canonicalization Algorithms and Their Pitfalls
- XML Encryption (XMLenc)
- Certificate Formats and Key Transport
- Signing Assertions versus Enveloping Assertions
- Key Discovery from Metadata
Chapter 8: SAML Metadata and Trust Configuration
- The EntityDescriptor and Its Children
- Endpoints and Bindings in Metadata
- Certificate Publication and Key Roles
- Entity Categories and Attribute Authority Metadata
- Metadata Aggregation and Chaining
- Operational Lifecycle: Updates, Revocation, and Rotation
Chapter 9: OAuth 2.0: Delegated Authorization
- The Authorization Problem and Delegation
- OAuth’s Four Roles
- Tokens: Access Tokens, Refresh Tokens, and Their Invariants
- Grant Types and What They Represent
- Scopes, Permissions, and Resource Boundaries
Chapter 10: OAuth 2.0: Grant Types and Protocol Flows
- The Authorization Code Grant
- The Implicit Grant (and Why It Is Deprecated)
- Client Credentials Grant (Machine-to-Machine)
- Resource Owner Password Credentials Grant (and Why It Is Deprecated)
- Authorization Code Grant with PKCE
- Token Endpoint Authentication Methods
Chapter 11: OAuth 2.0 Security Requirements
- TLS Requirements and Certificate Validation
- Client Authentication at the Token Endpoint
- Redirect URI Validation and Open Redirect Prevention
- The State Parameter and CSRF Prevention
- Token Endpoint Security
- Secure Token Handling and Storage
Chapter 12: OpenID Connect: Identity Layer on OAuth
- What OpenID Connect Adds Over OAuth 2.0
- The ID Token: Structure, Claims, and Validation Rules
- Authorization Code Flow with OpenID Connect
- The userinfo Endpoint and Claim Sets
- RP-Initiated Logout
- Pushed Authorization Requests (PAR)
Chapter 13: JWT, JWS, JWE, and JWK: The Token Formats
- JWT Syntax and Claims: Header, Payload, Signature
- JWS: Signing Algorithms (RS256, ES256, PS256, etc.)
- JWE: Encryption and Key Wrapping
- JWK and JWKS: Key Representation and Discovery
- Algorithm Confusion and the none Attack
- Token Validation: Issuer, Audience, Expiration, and Signature
Chapter 14: OpenID Connect Discovery and Registration
- The Authorization Server Metadata Document
- The Client Metadata Registration
- Well-Known Discovery URLs
- Dynamic Client Registration Protocol
- Front-Channel versus Back-Channel Discovery
- Discovering Supported Algorithms and Constraints
Chapter 15: PKCE: Securing Public Clients
- The Public Client Problem
- Authorization Code Interception Attack
- PKCE: Protocol Mechanics and Code Challenges
- PKCE with Authorization Code Flow
- PKCE with OIDC
- Why PKCE Belongs Everywhere
Chapter 16: Implementing OAuth and OpenID Connect: Authorization Server
- Architecture: Endpoints, Storage, and Dependencies
- Client Registry and Configuration
- The Authorization Endpoint
- The Token Endpoint
- JWKS and Discovery Endpoints
- Running the Server: Setup and Test
Chapter 17: Implementing Relying Parties and Clients
- Web App with Authorization Code + PKCE (Backend Session)
- Single-Page Application with PKCE
- Machine-to-Machine with Client Credentials
- Token Validation Middleware
- Error Handling and Logging
Chapter 18: Implementing SAML Service Providers
- SP Metadata Generation
- Authentication Request Construction
- Assertion Validation and Signature Verification
- SAML Response Processing
- Single Logout Handling
- Complete SP Implementation Walkthrough
Chapter 19: Advanced OAuth Patterns
- Token Introspection Endpoint
- Token Revocation
- OAuth Token Exchange (RFC 8693)
- JWT Secured Authorization Response Mode (JAR/JARM)
- Device Authorization Grant (for TVs and IoT)
- Mutual TLS Client Authentication
Chapter 20: OAuth and OIDC for APIs
- Reference Tokens versus Self-Contained Tokens
- The Resource Server as an OAuth Participant
- Validating Tokens in API Gateway and Service Mesh
- Audience Claims and Multi-API Authorization
- Fine-Grained Authorization with Scopes and Claims
- API Security: Rate Limiting, CORS, and Transport
Chapter 21: Sessions, Cookies, and Browser Security
- Session State Models
- Cookie Attributes and Security
- CSRF Defense Strategies
- Session Fixation and Session Hijacking
- Secure Logout and Session Termination
- SameSite: How It Helps and Its Limitations
Chapter 22: Authentication Attack Surface: OAuth and OIDC
- CSRF and State Parameter Bypass
- Login CSRF (Authorization Server CSRF)
- Client Authentication Confusion Attacks
- Redirect URI Manipulation
- ID Token Substitution Attacks
- Scope Manipulation and Privilege Escalation
- Token Leakage Through URLs
- PKCE Downgrade Attacks
Chapter 23: SAML Attack Surface
- XML External Entity (XXE) Attacks
- XML Signature Wrapping Attacks
- Alias and Key Confusion Attacks
- Assertion Replay and Forgery
- NameID and Attribute Manipulation
- Insecure XML Parsing
Chapter 24: Identity Architecture Patterns
- Backend-for-Frontend (BFF) Architecture
- Microservices and Internal Token Propagation
- Multi-Tenant Identity and Isolation
- Workload Identity for Kubernetes and Cloud
- Enterprise Federation Strategies
- SaaS Identity Architecture
Chapter 25: Migration: From SAML to Modern Protocols
- Assessing the Current Federation Landscape
- Protocol Bridging and Translation
- User Migration and Credential Strategies
- Parallel Operation During Transition
- Breaking Changes and Compatibility
- Post-Migration Security Hardening
Chapter 26: Operational Identity Engineering
- Key and Certificate Lifecycle Management
- Secrets Management and Rotation
- Logging and Auditing Without Leaking Credentials
- Observability and Debugging Identity Flows
- Incident Response for Key Compromise
- Availability and Disaster Recovery
Chapter 27: Design Choices and Trade-Offs
- SAML versus OIDC: When Each Makes Sense
- JWT versus Reference Tokens
- Centralized Identity versus Federated versus Hybrid
- Symmetric versus Asymmetric Token Validation
- Short-Lived versus Long-Lived Tokens
- Vendor Lock-In versus Open Standards