{"id":22661146,"url":"https://github.com/jujiro/wep-app-sec","last_synced_at":"2026-04-24T11:37:38.362Z","repository":{"id":169508389,"uuid":"186515560","full_name":"jujiro/wep-app-sec","owner":"jujiro","description":"A compact ASP.Net application to learn about securing web applications and apis.","archived":false,"fork":false,"pushed_at":"2019-05-22T15:28:55.000Z","size":22,"stargazers_count":0,"open_issues_count":0,"forks_count":0,"subscribers_count":1,"default_branch":"master","last_synced_at":"2025-06-20T19:58:04.215Z","etag":null,"topics":["api-secure","apis","asp-net","aspnet","aspnet-mvc","dotnet","learning-by-doing","oauth2"],"latest_commit_sha":null,"homepage":null,"language":"C#","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/jujiro.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2019-05-14T00:36:52.000Z","updated_at":"2019-05-22T15:28:57.000Z","dependencies_parsed_at":"2023-07-17T17:21:11.099Z","dependency_job_id":null,"html_url":"https://github.com/jujiro/wep-app-sec","commit_stats":null,"previous_names":["jujiro/wep-app-sec"],"tags_count":0,"template":false,"template_full_name":null,"purl":"pkg:github/jujiro/wep-app-sec","repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jujiro%2Fwep-app-sec","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jujiro%2Fwep-app-sec/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jujiro%2Fwep-app-sec/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jujiro%2Fwep-app-sec/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/jujiro","download_url":"https://codeload.github.com/jujiro/wep-app-sec/tar.gz/refs/heads/master","sbom_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/jujiro%2Fwep-app-sec/sbom","scorecard":null,"host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":286080680,"owners_count":32222135,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2026-04-24T10:26:35.452Z","status":"ssl_error","status_checked_at":"2026-04-24T10:25:27.643Z","response_time":64,"last_error":"SSL_connect returned=1 errno=0 peeraddr=140.82.121.5:443 state=error: unexpected eof while reading","robots_txt_status":"success","robots_txt_updated_at":"2025-07-24T06:49:26.215Z","robots_txt_url":"https://github.com/robots.txt","online":false,"can_crawl_api":true,"host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["api-secure","apis","asp-net","aspnet","aspnet-mvc","dotnet","learning-by-doing","oauth2"],"created_at":"2024-12-09T11:14:12.518Z","updated_at":"2026-04-24T11:37:38.357Z","avatar_url":"https://github.com/jujiro.png","language":"C#","funding_links":[],"categories":[],"sub_categories":[],"readme":"# wep-app-sec\nA compact ASP.Net application to learn about securing web applications and apis.\n\n## Introduction\nBeing a developer for over three decades I have been dealing with with the new keywords, terminology, along with the new and exciting technology, all the time.  Being an old-timer, and a strong proponent of KISS (Keep It Simple and Stupid,) I sometimes feel lost.  In those situations, I try to simplify stuff for others like me, who perhaps can benefit with my work.  This project is along the same lines.\n\nIf you are new to this subject, I suggest you to watch a very simple slideshow I prepared on this topic.\n[https://www.ipcolony.com/#blog-web-security]\n\n## What you will learn ##\nUsing this project you will learn pretty much how OAUTH works, though the project itself does not use it.\n\nThe following items are covered in the project.\n* Forcing https for your site\n* Password validation against stored hash\n* Returning a token after authentication\n* Using token for for subsequent conversation\n* Maintaining the tokens on the server side using a simple thread safe list\n* Securing Api methods\n* Adding added authorization to Api methods so that only selected users can use it\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjujiro%2Fwep-app-sec","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fjujiro%2Fwep-app-sec","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fjujiro%2Fwep-app-sec/lists"}