My name is NOT nobody
Explanation of the term authentication and its properties
Concept of Authentication in Computing
Authentication is the act of verifying the identity of a user, which can be a person, an application, or a device. This process occurs through various factors, which may include what the user "knows," what the user "possesses," and what the user "is".
- Knowledge: The user can demonstrate knowledge of a password or respond to a challenge, such as a one-time password (e.g., TOTP).
- Possession: The user can demonstrate possession of a hardware or software token, or a security device such as a mobile phone.
- Biometric Characteristics: The user can be identified through biometric traits such as fingerprints or facial recognition.
When authentication requires more than one factor, it is referred to as multi-factor authentication.
Concept of Session
Some applications allow users to remain authenticated for only a limited period of time before requiring them to re-authenticate. This is done to verify that the user is still legitimate.
The duration of the session depends on the sensitivity of the application and the risk of exposure. For more information on session management, it is recommended to consult the dedicated page by OWASP.
Session Management
Since HTTP is "stateless," applications provide users with session identifiers (tokens) that are exchanged for the duration of the session. Cookies are commonly used for this purpose:
- PHPSESSID (PHP)
- JSESSIONID (J2EE)
- ASP.NET_SessionId (ASP .NET), etc.
These are preferred over saving tokens in memory spaces like the browser's localStorage, which are more vulnerable to potential malicious scripts.
For session cookies, it is good practice to set the "http only" flag, which prevents access to the cookie by JavaScript, making session hijacking more difficult in case of XSS (Cross Site Scripting) attacks. It is also advisable to set the "secure" attribute to ensure cookie exchange only over HTTPS.
Other session implementations use:
- URL parameters or arguments
- Body parameters of the request
- Custom HTTP headers
Risks Associated with Incorrect Configurations
Authentication in an application is a critical aspect of software security. The main security risks according to the OWASP 2021 list include:
- Violation of the principle of least privilege or default deny
- Bypassing access controls (modifying the URL, internal application state, etc.)
- Allowing to view or edit another user's account (by providing their unique identifier)
- Accessing the API with missing access controls
- Elevation of privilege (acting as a user without being logged in)
- Metadata manipulation (e.g., replaying or tampering with a JWT or access control token)
- CORS (Cross-Origin Resource Sharing) misconfiguration (allows API access from unauthorized/untrusted origins)
- Forcing browsing to authenticated pages as an unauthenticated user or to privileged pages as a standard user.
Popular Authentication Frameworks
- SAML 2.0
- OAuth 2.0
- OpenID Connect
In the future, dedicated articles will be published on these frameworks to provide a more detailed explanation of their functioning. In general, these frameworks are used to centrally manage authentication;
Through an identity provider, users are allowed to access multiple applications with a single authentication to enhance the overall security of the architecture.
To be more precise, OAuth is primarily used for the purpose of authorization rather than authentication. These differences will be explained more thoroughly in the articles of the individual frameworks.
Session Management in Laravel
There are many libraries that allow implementing various authentication flows in Laravel.
The most common implementation uses a session cookie, whose identifier is updated with every request.
Configuration values can be set in the configuration file config/session.php.