Minimal NIST/OWASP-compliant auth implementation for Cloudflare Workers
Details
- External ID
- 46944084
- Source
- HN
- Company
- —
- Product
- Minimal NIST/OWASP-compliant auth implementation for Cloudflare Workers
- Website domain
- github.com
- Launched
- Feb. 9, 2026
- Cohort
- —
- Upvotes
- 33
- Upvotes percentile
- 0.7553908355795148
- Tags
- —
- Fetched at
- Sept. 7, 2026, 9:26 p.m.
- Updated at
- Sept. 7, 2026, 9:26 p.m.
Description
This is an educational reference implementation showing how to build reasonably secure, standards-compliant authentication from first principles on Cloudflare Workers.Stack: Hono, Turso (libSQL), PBKDF2-SHA384 + normalization + common-password checks, JWT access + refresh tokens with revocation support, HTTP-only SameSite cookies, device tracking.It's deliberately minimal — no OAuth, no passkeys, no magic links, no rate limiting — because the goal is clarity and auditability.I wrote it mainly to deeply understand edge-runtime auth constraints and to have a clean Apache-2.0 example that follows NIST SP 800-63B / SP 800-132 and OWASP guidance.For production I'd almost always reach for Better Auth instead (https://www.better-auth.com) — this repo is not trying to compete with it.Live demo: https://private-landing.vhsdev.workers.dev/Repo: https://github.com/vhscom/private-landingHappy to answer questions about the crypto choices, the refresh token revocation pattern, Turso schema, constant-time comparison, unicode pitfalls, etc.
Enrichment
- Theme
- self-hosted infrastructure and security tools
- Vertical
- Horizontal
- Function
- Dev tools
- Audience
- Developer
- AI stance
- Not AI
- Project type
- Hobby / open-source project
- Normalized one-liner
- nist/owasp-compliant auth for cloudflare workers
- Manually corrected
- False
Could you build this?
Yes It is a reference implementation of user authentication using standard WebCrypto APIs (PBKDF2), Hono, and SQLite/libSQL on Cloudflare Workers. An AI assistant can generate this exact standards-based authentication boilerplate in a few prompts.
Discussion
10 comments analyzed.
Competitors mentioned: Production-grade auth frameworks, Cloudflare Durable Objects
Concerns raised: Missing NIST SP 800-63B compliance requirements, Timing attack vulnerability in database select before password validation, No enforced min/max length on stored secrets and account identifiers, Missing email normalization, AI-generated code with potential validity issues
Feature requests: DNS/MX validation for email addresses, Constant-time password comparison, Unicode normalization (NFC/NFKC) before hashing, Rate limiting via distributed locks for multi-request mitigation, Random delay on failed login attempts to prevent timing attacks
Competitors
Other products that read as similar to this one — 69 launches clear the similarity bar, closest 8 shown.
Attention rank: #19 of 70 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).
Launched 103 days after the earliest competitor.
- Open Passkey · hn · 2026-04-19 · 10 upvotes · similarity 0.51
- Anonymous age verification with passkey-powered encryption · hn · 2026-08-19 · 45 upvotes · similarity 0.43
- I built an HTTP client that perfectly mimics Chrome 142 · hn · 2025-11-08 · 39 upvotes · similarity 0.42
- LukaOTP · ph · 2026-09-25 · 1 upvotes · similarity 0.41
- Oblivious HTTP for Go · hn · 2025-10-29 · 10 upvotes · similarity 0.40
- A dynamic key-value IP allowlist for Nginx · hn · 2025-12-30 · 5 upvotes · similarity 0.38
- AuthPlane · hn · 2026-06-17 · 7 upvotes · similarity 0.38
- Oauthcli · hn · 2026-09-13 · 5 upvotes · similarity 0.38
Other launches for this product
- No other launches for this product.
Same idea, different domain
Nobody's really built a dev tools tool for Sales yet.