<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Versola</title><description>Versola — разработка серверов аутентификации и авторизации OAuth 2.0 / OpenID Connect для бизнеса</description><link>https://blog.versola.kz/</link><item><title>One Proxy, Every Authorization Decision: Inside Versola&apos;s Edge</title><link>https://blog.versola.kz/edge-proxy-policy-engine/</link><guid isPermaLink="true">https://blog.versola.kz/edge-proxy-policy-engine/</guid><description>How Versola&apos;s edge proxy turns permissions, CEL-based dynamic rules, RFC 9470 step-up and identity injection into one ordered pipeline in front of every service, with a single observability layer covering all of it.</description><pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Front-Channel and Back-Channel Logout: Why Your Logout Is Broken</title><link>https://blog.versola.kz/front-channel-back-channel-logout/</link><guid isPermaLink="true">https://blog.versola.kz/front-channel-back-channel-logout/</guid><description>Logging out of one app does not log a user out of every app in an SSO session. How front-channel and back-channel OIDC logout actually work, real HTTP examples, and where each one silently fails.</description><pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate></item><item><title>OAuth 2.1: What Actually Changed, and What &quot;Supporting&quot; It Really Means</title><link>https://blog.versola.kz/oauth-21-explained/</link><guid isPermaLink="true">https://blog.versola.kz/oauth-21-explained/</guid><description>OAuth 2.1 is still a draft, not an RFC, and it does not add anything new. It deletes the parts of OAuth 2.0 that kept causing the same five vulnerabilities. What each removal closes, and what &quot;OAuth 2.1 compliant&quot; should mean in practice.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The Long Goodbye: Password Hashing in the Age of Passkeys</title><link>https://blog.versola.kz/password-hashing-passkeys/</link><guid isPermaLink="true">https://blog.versola.kz/password-hashing-passkeys/</guid><description>Passwords are being phased out, and you still have to store them correctly. A practical tour of hashing, the attack vectors that actually get used, and the one failure mode nobody warns you about: your own defense becoming a denial-of-service vector.</description><pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Один прокси, все авторизационные решения</title><link>https://blog.versola.kz/ru/edge-proxy-policy-engine/</link><guid isPermaLink="true">https://blog.versola.kz/ru/edge-proxy-policy-engine/</guid><description>Как edge-прокси Versola сводит права доступа, динамические CEL-правила, step-up по RFC 9470 и подстановку идентичности в один упорядоченный пайплайн перед каждым сервисом — и один слой наблюдаемости на все это.</description><pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate></item><item><title>Front-Channel и Back-Channel Logout: почему ваш логаут не работает</title><link>https://blog.versola.kz/ru/front-channel-back-channel-logout/</link><guid isPermaLink="true">https://blog.versola.kz/ru/front-channel-back-channel-logout/</guid><description>Выход из одного приложения не завершает сессию пользователя во всех приложениях в рамках SSO. Как на самом деле работают front-channel и back-channel logout в OIDC, реальные HTTP-примеры и где каждый из них незаметно ломается.</description><pubDate>Fri, 21 Aug 2026 00:00:00 GMT</pubDate></item><item><title>OAuth 2.1: что реально изменилось и что значит его «поддерживать»</title><link>https://blog.versola.kz/ru/oauth-21-explained/</link><guid isPermaLink="true">https://blog.versola.kz/ru/oauth-21-explained/</guid><description>OAuth 2.1 — все еще черновик, а не RFC, и ничего нового он не добавляет. Он вычеркивает из OAuth 2.0 то, что годами порождало одни и те же уязвимости. Что закрывает каждое удаление и что должно означать «соответствие OAuth 2.1» на практике.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Пароли в эпоху passkeys: как их хранить и как не уронить этим свой же сервис</title><link>https://blog.versola.kz/ru/password-hashing-passkeys/</link><guid isPermaLink="true">https://blog.versola.kz/ru/password-hashing-passkeys/</guid><description>Пароли отменяют уже который год, а хранить их все равно приходится. Разбираем соль, перец и Argon2id, реальные атаки вместо книжных, и отказ, о котором почти не пишут: когда защита паролей превращается в способ положить собственный сервис.</description><pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Почему JWT нельзя отозвать, и единственная схема, где можно</title><link>https://blog.versola.kz/ru/why-jwt-cannot-be-revoked/</link><guid isPermaLink="true">https://blog.versola.kz/ru/why-jwt-cannot-be-revoked/</guid><description>Как отозвать JWT до истечения срока, почему черный список по jti в Redis - это ответ, к которому приходят все, и как Versola edge делает это через Postgres LISTEN/NOTIFY: реальные HTTP-примеры.</description><pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Why You Can&apos;t Revoke a JWT, and the One Setup Where You Can</title><link>https://blog.versola.kz/why-jwt-cannot-be-revoked/</link><guid isPermaLink="true">https://blog.versola.kz/why-jwt-cannot-be-revoked/</guid><description>How to revoke a JWT before it expires, why a jti blacklist in Redis is the answer everyone reaches for, and how Versola edge does it with Postgres LISTEN/NOTIFY instead: real HTTP examples.</description><pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate></item></channel></rss>