Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Minimal NIST/OWASP-compliant auth implementation for Cloudflare Workers

Details

External ID
46944084
Source
HN
Company
—
Product
Minimal NIST/OWASP-compliant auth implementation for Cloudflare Workers
Website domain
github.com
Launched
Feb. 9, 2026
Cohort
—
Upvotes
33
Upvotes percentile
0.7553908355795148
Tags
—
Fetched at
Sept. 7, 2026, 9:26 p.m.
Updated at
Sept. 7, 2026, 9:26 p.m.

Description

This is an educational reference implementation showing how to build reasonably secure, standards-compliant authentication from first principles on Cloudflare Workers.Stack: Hono, Turso (libSQL), PBKDF2-SHA384 + normalization + common-password checks, JWT access + refresh tokens with revocation support, HTTP-only SameSite cookies, device tracking.It's deliberately minimal — no OAuth, no passkeys, no magic links, no rate limiting — because the goal is clarity and auditability.I wrote it mainly to deeply understand edge-runtime auth constraints and to have a clean Apache-2.0 example that follows NIST SP 800-63B / SP 800-132 and OWASP guidance.For production I'd almost always reach for Better Auth instead (https://www.better-auth.com) — this repo is not trying to compete with it.Live demo: https://private-landing.vhsdev.workers.dev/Repo: https://github.com/vhscom/private-landingHappy to answer questions about the crypto choices, the refresh token revocation pattern, Turso schema, constant-time comparison, unicode pitfalls, etc.

Enrichment

Theme
self-hosted infrastructure and security tools
Vertical
Horizontal
Function
Dev tools
Audience
Developer
AI stance
Not AI
Project type
Hobby / open-source project
Normalized one-liner
nist/owasp-compliant auth for cloudflare workers
Manually corrected
False

Could you build this?

Yes It is a reference implementation of user authentication using standard WebCrypto APIs (PBKDF2), Hono, and SQLite/libSQL on Cloudflare Workers. An AI assistant can generate this exact standards-based authentication boilerplate in a few prompts.

Discussion

10 comments analyzed.

Competitors mentioned: Production-grade auth frameworks, Cloudflare Durable Objects

Concerns raised: Missing NIST SP 800-63B compliance requirements, Timing attack vulnerability in database select before password validation, No enforced min/max length on stored secrets and account identifiers, Missing email normalization, AI-generated code with potential validity issues

Feature requests: DNS/MX validation for email addresses, Constant-time password comparison, Unicode normalization (NFC/NFKC) before hashing, Rate limiting via distributed locks for multi-request mitigation, Random delay on failed login attempts to prevent timing attacks

Competitors

Other products that read as similar to this one — 69 launches clear the similarity bar, closest 8 shown.

Attention rank: #19 of 70 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 103 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a dev tools tool for Sales yet.