frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Minimal NIST/OWASP-compliant auth implementation for Cloudflare Workers

https://github.com/vhscom/private-landing
11•vhsdev•1h ago
This is an educational reference implementation showing how to build reasonably secure, standards-compliant authentication from first principles on Cloudflare Workers.

Stack: Hono, Turso (libSQL), PBKDF2-SHA384 + normalization + common-password checks, JWT access + refresh tokens with revocation support, HTTP-only SameSite cookies, device tracking.

It's deliberately minimal — no OAuth, no passkeys, no magic links, no rate limiting — because the goal is clarity and auditability.

I wrote it mainly to deeply understand edge-runtime auth constraints and to have a clean Apache-2.0 example that follows NIST SP 800-63B / SP 800-132 and OWASP guidance.

For production I'd almost always reach for Better Auth instead (https://www.better-auth.com) — this repo is not trying to compete with it.

Live demo: https://private-landing.vhsdev.workers.dev/

Repo: https://github.com/vhscom/private-landing

Happy to answer questions about the crypto choices, the refresh token revocation pattern, Turso schema, constant-time comparison, unicode pitfalls, etc.

Comments

TheTaytay•28m ago
Thank you for writing/publishing this. I especially appreciate the prominent warning at the top not to mistake it for a production library and to suggest an alternative. (It’s surprising to me how often people forget to add disclaimers like that to their code.)
vhsdev•26m ago
Appreciate it, TheTaytay!
usefulposter•24m ago
Oy.

Who specifically is this intended for? It's a wonder that the model didn't spice things up with some compliance catnip like FIPS.

I would be curious to see the prompts used to create this.

At present, I don't think there could be a better example of applicability of Brandolini's law.

vhsdev•19m ago
Everything you or your agent need to see is in the commit history.

A raycasting engine in 7 easy steps

https://austinhenley.com/blog/raycasting.html
1•ibobev•1m ago•0 comments

Constraint Propagation for Fun

https://eli.li/constraint-propagation-for-fun
1•ibobev•1m ago•0 comments

Python Syntax compiles to Java source code – meet Java++

https://github.com/CrimsonDemon567PC/JavaPP
1•CrimsonDemon567•1m ago•0 comments

Jony Ive Designed Ferrari Luce EV Interior

https://www.topgear.com/car-news/electric/official-ferraris-first-ev-called-luce-interior-apples-...
1•elxr•1m ago•0 comments

OCapN and Structural Authority in Agentic AI

https://serefayar.substack.com/p/ocapn-and-structural-authority-in-agentic-ai
2•serefayar•2m ago•0 comments

Added OTEL Observability to OpenClaw agents full GenAI spec support

https://github.com/openclaw/openclaw/pull/11100
3•draismaa•4m ago•2 comments

Learn Weird Programming Languages

https://okienko.day/posts/2026-02-06-weird-languages.html
2•hubertmalkowski•4m ago•0 comments

Japan LLC has been trading its way out of a fiscal hole

https://www.ft.com/content/f7d3f20c-b303-4f6c-b4a0-8ee8906ae155
2•throwaway2037•5m ago•1 comments

Vending-Bench 2

https://andonlabs.com/evals/vending-bench-2
2•samdung•5m ago•0 comments

Danish Red Street Lighting Solves a Problem Every City Has

https://www.newsweek.com/denmark-red-street-lighting-gladsaxe-11488484
2•sohkamyung•6m ago•0 comments

Show HN: Speaklone – Native voice cloning for Mac, runs on-device

https://speaklone.com
2•SciFiDev•6m ago•1 comments

Extract Audio from Video

https://www.eranol.com/tools/extract-audio
2•harshalone•6m ago•0 comments

The Claude Code plugin that replaced my visual workflow

https://twitter.com/omarsar0/status/2020546189536399568
2•pretext•7m ago•0 comments

The Styx Architecture for Distributed Systems (1999)

https://inferno-os.org/inferno/papers/styx.html
1•luismedel•8m ago•0 comments

Are you a digital sharecropper? (2009)

https://blog.codinghorror.com/are-you-a-digital-sharecropper/
1•zeckalpha•9m ago•0 comments

Show HN: Simulation Studio Inside ArchtSoft

https://archtsoft.com
1•SougataAS•10m ago•0 comments

SpaceX prioritizes lunar 'self-growing city' over Mars project

https://www.reuters.com/science/musk-says-spacex-prioritise-building-self-growing-city-moon-2026-...
1•janpot•10m ago•0 comments

Profiling Swift Applications on Windows and macOS with Tracy

https://compositorapp.com/blog/2026-02-07/Tracy/
1•serhack_•10m ago•0 comments

React-based TUI framework based on Yoga and react-reconciler. Full Flexbox

https://github.com/nick-skriabin/glyph
1•nicholasrq•11m ago•0 comments

Botkeeper Shuts Down

https://www.botkeeper.com/to-the-botkeeper-community
2•danso•12m ago•1 comments

Show HN: Browser Terminal Use – A Local-to-Cloud Execution Bridge for LLM Agents

https://github.com/chaokunyang/browser-terminal-use
1•chaokunyang•15m ago•0 comments

Show HN: Claude-Pipe – A 1k LOC Bridge from Claude Code to Telegram/Discord

https://github.com/georgi/claude-pipe
1•mmgeorgi•17m ago•0 comments

Usage_rules makes agents better at Elixir [video]

https://www.youtube.com/watch?v=W_qO7ouLQz4
1•borromakot•17m ago•0 comments

OpenClaw Partners with VirusTotal for Skill Security

https://openclaw.ai/blog/virustotal-partnership
1•quanweidu•17m ago•0 comments

Self-Management Tips for Remote Workers to Avoid Burnout in 2026

https://saveku.com/blog/5-self-management-tips-for-remote-workers-to-avoid-burnout
1•roywj•19m ago•0 comments

Building an Open-Source Claude Code-Style Agent in Python

https://blog.wiseprobe.io/posts/building-patchpal/
1•wiseprobe•19m ago•0 comments

Why Canvas Breaks Your Screen Recorder (and What to Do Instead)

https://sendrec.eu/blog/why-canvas-breaks-your-screen-recorder/
1•alexneamtu•20m ago•0 comments

First Proof

https://1stproof.org/
1•burrito_brain•22m ago•0 comments

Ask HN: Will Tesla ever be truly self driving?

1•roschdal•22m ago•2 comments

Show HN: Codesession-CLI – Teach your AI agent to track its own token costs

1•nesh23•23m ago•1 comments