Sign in

Erwin

@vandervalk.pro
46 followers 54 following 40 posts

Software Architect | c# | dotNet | cloud | Parent | Swordsman | Metal Head | History and Science Enthusiast| Principal Engineer @ Duende Software

PostsRepliesMedia
Erwin @vandervalk.pro · 15/04/2026
Having used weave and weave fleet a lot, i can say it’s awesome!
000
Erwin @vandervalk.pro · 22/07/2025
I wanted an inspirational picture that describes 'the next steps' for a product presentation. What I got was an image of a one legged person committing suicide.
020
Erwin @vandervalk.pro · 03/06/2025
"LLM's are great for interrogating large pieces of text" Only if you don't care if the result is actually correct. Like with specs.
from the actual specfrom chatgtp
020
Reposted by Erwin
Duende Software @duendesoftware.com · 19/05/2025
Livestream coming up! 📺 Token Management: Applying the Duende Backend for Frontend (BFF) Security Framework 🗓️ June 4, 2025 ⏱️ 10 EST / 16:00 CEST / 14:00 UTC 🗣️ Speaker: Erwin van der Valk Register here: duende.link/wj42025 #dotnet #security #bff
duende.link
Token Management
We help companies using .NET to build identity and access control solutions for modern applications.
034
Reposted by Erwin
Richard Campbell @richcampbell.bsky.social · 15/05/2025
OAuth 2.0 is powerful, but simple when it comes to dealing with multiple clients. @vandervalk.pro talks on .NET Rocks at www.dotnetrocks.com/details/1950 about using the Backend for Frontend (BFF) Security Framework to simplify your OAuth 2.0 implementation!
dotnetrocks.com
.NET Rocks!
.NET Rocks! is a weekly talk show for anyone interested in programming on the Microsoft .NET platform. The shows range from introductory information to hardcore geekiness.
062
Reposted by Erwin
Duende Software @duendesoftware.com · 15/05/2025
This week's .NET Rocks! features Erwin van der Valk talking about the Backend for Frontend (BFF) pattern and how it can be used to secure browser-based applications. Tune in at duende.link/1950dnr 🎧 #dotnet #bff #security #aspnetcore
duende.link
.NET Rocks!
.NET Rocks! is a weekly talk show for anyone interested in programming on the Microsoft .NET platform. The shows range from introductory information to hardcore geekiness.
025
Erwin @vandervalk.pro · 15/05/2025
Absolutely honored to have been on the Dotnet Rocks show with @richcampbell.bsky.social and @carlfranklin.bsky.social to talk about the BFF security pattern. Check it out at: www.dotnetrocks.com/details/1950
bsky.app
163
Reposted by Erwin
Duende Software @duendesoftware.com · 02/05/2025
Data Protection in #aspnetcore is an essential part of securing applications while maintaining the capabilities to scale out to meet user demand. But how does it work? Learn more on our blog: duende.link/ywet6ag #dotnet #aspnetcore #identity
duende.link
Data Protection for ASP.NET Core Developers and Duende IdentityServer
We help companies using .NET to build identity and access control solutions for modern applications.
044
Reposted by Erwin
Duende Software @duendesoftware.com · 30/04/2025
Managing OpenAPI Specifications with Backend For Frontend and Swagger UI 📚 We'll briefly recap the BFF pattern, and then dive into a sample & learn how to reveal your OpenAPI specifications securely. duende.link/73hbw12 #dotnet #security #bff #openapi #aspnetcore
036
Erwin @vandervalk.pro · 16/04/2025
I love how spotify announced a price increase and then has a big outtage. It’s what my motivation to move to something else needed.
110
Reposted by Erwin
Duende Software @duendesoftware.com · 10/04/2025
Fresh Duende.AccessTokenManagement release candidate! 🔑 Named keys for IDistributedCache injection 💸 HybridCache (preview) 📊 Open Telemetry metrics, logs and traces 🏕️ Externalized cache key generation 🎉 and more! github.com/DuendeSoftwa... #dotnet #oidc #security
github.com
Release Duende.AccessTokenManagment 4.0.0 - RC1 · DuendeSoftware/foss
This release contains several important improvements and changes: Named key support for injecting a specific IDistributedCache instance. A preview feature that allows the use of HybridCache. This ...
054
Reposted by Erwin
Duende Software @duendesoftware.com · 09/04/2025
Secure your #VueJS apps with OpenID Connect & the BFF pattern! 🔒 We’ll look at the basic architecture of a BFF solution, the responsibilities of each component, and how it all fits together. duende.link/eshdrq4 #Security #OAuth2 #OpenIDConnect #dotnet
036
Reposted by Erwin
Duende Software @duendesoftware.com · 31/03/2025
How are you extending Duende.AccessTokenManagement? 🧐 We are looking at minimizing the public surface area of the library, and introducing targeted extensibility points. Weigh in and help shape what this will look like in v4 👉 github.com/orgs/DuendeS... #dotnet #security #oidc
github.com
How are you extending Duende.AccessTokenManagement? · DuendeSoftware · Discussion #140
As we work on adding new features to AccessTokenManagement, we've encountered some challenges with its current design, particularly regarding extensibility. The existing approach leans towards inhe...
054
Erwin @vandervalk.pro · 23/03/2025
I hope they didn’t put the plates in skewed… otherwise, there is no hope left.
000
Reposted by Erwin
Joe DeCock @jmdc.dev · 18/03/2025
Congrats to @vandervalk.pro and the whole team! I'm really excited to finally have our Blazor BFF Bits out there in the wild!
022
Reposted by Erwin
Duende Software @duendesoftware.com · 18/03/2025
Today brings you #IdentityServer 7.2! 🎁 1️⃣ Strict Audience Validation ensures that the audience is equal to the issuer and validates the token’s typ value. 2️⃣ Discovery Document Caching helps throughput in large deployments And more! 👉 duende.link/hjdsk82 #dotnet #aspnetcore
079
Reposted by Erwin
Duende Software @duendesoftware.com · 17/03/2025
Good news! We just released Duende Backend-for-Frontend (BFF) Security Framework V3. All the necessary components to secure browser-based frontends (e.g. SPAs or #Blazor applications) with #aspnetcore backends. duende.link/iuq3t4n #dotnet
146
Erwin @vandervalk.pro · 25/02/2025
This would be funny if it wasn’t accurate
010
Reposted by Erwin
Duende Software @duendesoftware.com · 19/02/2025
Using Duende.AccessTokenManagement? Upgrade to v3.2.0! Previous versions contain a race condition when requesting access tokens which may trigger errors in specific cases. Advisory: github.com/DuendeSoftwa... Discussion: github.com/orgs/DuendeS... #IdentityServer #Security #dotnet
github.com
Duende.AccessTokenManagement race condition when concurrently retrieving customized Client Credentials Access Tokens
### Summary Duende.AccessTokenManagement contains a race condition when requesting access tokens using the client credentials flow. Concurrent requests to obtain an access token using differing pr...
034
Reposted by Erwin
Maarten Balliauw @maartenballiauw.be · 06/02/2025
Let's try this GitHub discussions thing... Who's still on IdentityServer 4, and why? #dotnet github.com/orgs/DuendeS...
github.com
Who's still on IdentityServer 4, and why? · DuendeSoftware · Discussion #36
When looking at NuGet, I noticed IdentityServer 4 still has many downloads. Which makes me curious: who's still on IdentityServer 4, and why? Is it because your solution is locked on an older .NET ...
2412
Reposted by Erwin
Maarten Balliauw @maartenballiauw.be · 03/02/2025
If you're still on IdentityServer4, what's the reason?
203
Erwin @vandervalk.pro · 21/01/2025
Hmm… currently watching civil war. Not a feel good vibe. Especially not now.
000
Erwin @vandervalk.pro · 19/01/2025
forum.ncrunch.net/Default.aspx.... If you read the last comment from the author of NCrunch (Remco). NCrunch is a fantastic testrunner so it would be awesome if somehow NCrunch and Aspire could work together.
forum.ncrunch.net
Aspire - Build/Test Issues - NCrunch Forum
Aspire: Hi, Merry Christmas, all the best to you and all the developers - thanks for a great product. Today I stumbled on an issue however. In my existing solution, I wanted to start checking out Aspi...
100
Erwin @vandervalk.pro · 19/01/2025
Would this also help getting aspire projects to work under ncrunch?
100
Reposted by Erwin
Duende Software @duendesoftware.com · 15/01/2025
Duende IdentityServer v7.1.0 general availability release is now live. This release includes .NET 9 support, enhancements, bug fixes, performance improvements, and more. See the release notes: github.com/DuendeSoftwa... #dotnet
IdentityServer 7.1.0 is a significant release that includes:

.NET 9 support
Use of Duende.IdentityModel
New license usage helpers
Friendly READMEs in the NuGet packages
Improved log filtering when HTTP requests are aborted
Redaction of the subject token during token exchange
Improved extensibility of the ClientConfigurationStore in the Configuration API
Several bug fixes
Numerous small code quality and performance enhancements from the community
11312
Erwin @vandervalk.pro · 08/01/2025
000
Erwin @vandervalk.pro · 08/01/2025
Hot metal
200
Erwin @vandervalk.pro · 08/01/2025
Forged my own axe the other day, together with my son.
110
Erwin @vandervalk.pro · 04/01/2025
Don’t get wireless / wifi camera’s. They are very easily blocked by a wifi jammer.
110
Erwin @vandervalk.pro · 03/01/2025
Yeah, security has to be part of your process. It's not a 'task' you perform somewhere during the process and it's never complete.
000
Erwin @vandervalk.pro · 03/01/2025
Now I get to work again with an amazing team at @duendesoftware.com , in a very exiting space with people I really admire! Exciting times ahead!
221
Erwin @vandervalk.pro · 03/01/2025
I'm absolutely delighted to announce that i've joined @duendesoftware.com as a Principal Engineer. I truly enjoyed my time at YuzeData, where I got to work (again) with some of my amazing friends and I'm very proud of how much we have achieved. It's absolutely been a blast!
152
Erwin @vandervalk.pro · 23/12/2024
Gruffalo was one of my favorite bedtime story for the kids.
020
Erwin @vandervalk.pro · 18/12/2024
Has anybody else experienced slowdowns with .net 9 compilation vs .net 8? I'm noticing it especially in ncrunch.
000
Erwin @vandervalk.pro · 20/11/2024
I really hope so as well. Is there anything in the Bluesky architecture / capabilities that's going to prevent large botfarms and malicious / annoying actors from poisoning discussions here as well?
010
Reposted by Erwin
John Cutler @johncutle.fish · 20/11/2024
Some images from the Twitter years in a thread (since they are no longer accessible) 1/n
426262
Erwin @vandervalk.pro · 08/11/2024
I don’t…. But i add ‘dontsend’ as a recipient. Then when you try to send it, outlook asks who that is. I find this works better when preventing accidental sends during replies. Helped me many times already 😀
010
Erwin @vandervalk.pro · 04/11/2024
Time to polish the swords again…
000
Erwin @vandervalk.pro · 02/11/2024
Swordsmanship… nice
010
Erwin @vandervalk.pro · 31/10/2024
Anyway, internet is a dangerous place. Stay safe and keep your servers safe as well.
000
Erwin @vandervalk.pro · 31/10/2024
looking for /etc/passwd. Again, a variation of sharing your entire filesystem, but also a lovely way to find out which users are present on the system.
100
Erwin @vandervalk.pro · 31/10/2024
Looking for /windows/win.ini. (and variations of it). I was wondering why would anyone look for this file. But then I realized.. this would mean there are people who share their entire filesystem via the internet. Damn...
100
Erwin @vandervalk.pro · 31/10/2024
Looking for /query. This is quite generic, but I can imagine they are looking for open query endpoints. Ideally with nice SQL Injection vulnerabilities to exploit. I can't believe in 2024 SQL Injection is still in the OWASP top 10.
100
Erwin @vandervalk.pro · 31/10/2024
Looking for /geoserver/web. This is more specifically looking for a product called 'geoserver'. Apparently there's a whole number of (critical) vulnerabilities with this product. Unfortunately, if you use any software product, you need to keep on top of all security CVE's in that ecosystem.
100
Erwin @vandervalk.pro · 31/10/2024
Looking for eval-stdin.php. Apparently this is part of a php unit testing framework. That's odd, because normally unit testing is done on the build server only, but apparently several wordpress plugins just ship this. There's even some CVE's associated with it, such as: CVE-2017-9841.
100
Erwin @vandervalk.pro · 31/10/2024
Looking for /index.pl or index.php, index.cgi, index.cfm, index.asp, etc.. (many other variants). I think they are looking for misconfigured webservers would just serve the code when asked for it. They also appear to look for older software systems that may not be patched well.
100
Erwin @vandervalk.pro · 31/10/2024
Scanners looking for /sendgrid.env. Wow, what fun a malicious actor can have when they can send emails in your name.
100
Erwin @vandervalk.pro · 31/10/2024
Looking for config.php.bak files in various places. Apparently people put secrets in config.php files (again, not a good idea). But serving any file on the file system is never a good idea. Especially .bak files. Don't store secrets on the file system, but also, restrict what file types you serve.
100
Erwin @vandervalk.pro · 31/10/2024
Looking for /.env files. NodeJS apps can store environment settings there. Not a good idea to store secrets in this file, but even worse to serve it via the internet. Plenty of variants: /api/.env, /aws/.env,/aws/.env. Better idea to have secrets as machine environment variables (from KeyVault).
100
Erwin @vandervalk.pro · 31/10/2024
Some of the top things I'm finding:
100