AuthZ at top of OWASP 2023 top 10 list, New features added to Cerbos Cloud, Cerbos' Query Plan Adapter for Prisma
View in browser
Group 1126 (5)

Our July newsletter includes:

  • Updates to Cerbos - v0.29 of Cerbos

  • Stay tuned for the upcoming public beta launch of Cerbos Cloud - the solution that will help our users revolutionize the way they authorize

    • Cerbos Playground - write, test, and debug Cerbos policies in your browser
        • Cerbos events:
          • WeAreDevelopers World Congress: July 27-28 
          • Cloud Native London Meetup: August 2
          • The Developer-First Security Week: August 7-11
        • New blog posts on Cerbos.dev:
          • Authorization remains #1 issue - OWASP 2023 Top 10 List
          • Nested fields support with Prisma Query Plans
          • Cerbos adds major new features to Cerbos Cloud for streamlining the implementation and management of authorization policies at limitless scale
          • The future is stateless: It’s time to ensure your security is as scalable as your business
          • Driving impact through open source developer tooling | Emre Baran, Cerbos | Collision 2023
          • Unlocking cybersecurity: A deep dive into authentication vs authorization in software development

         

        You are receiving this email because either we have met, chatted, or you've visited our website cerbos.dev and asked us to keep you up-to-date. If you have been forwarded this email, you can subscribe and receive future updates directly from us. If you prefer not to receive these updates, you can unsubscribe below, but we hope you stay!

         

        Updates to Cerbos

        v0.29 of Cerbos

        The v0.29 release of Cerbos is packed with new features such as shared variables, support for globals, updates to scopes and more.

        • It’s now possible to share variable definitions between multiple policies using the new ExportVariables policy type.
        • A new globals object is available to policies at runtime to read environment-specific values defined in the configuration file of the Cerbos server.
        • When evaluating scoped policies, the default behaviour of Cerbos is to fail if a policy file with the requested scope doesn’t exist. You can now relax this requirement through a configuration setting.
        • This release also includes updates to the ListPolicies method on the Admin API to allow filtering and a couple of community contributions to support TLS on the Kafka log sink and improvements to the contents of the logs.

        You can find the full release notes here: v0.29.

         

        Cerbos events

        Events

        A big thank you to everyone who stopped by our booths at Collision and GopherCon EU, and chatted to Alex Olivier at London CTOs Unconference. Our team had a great time connecting with you.


        Looking ahead, we're excited to announce that we'll be attending several more events in the upcoming weeks. Join us at:

        • WeAreDevelopers World Congress in Berlin from July 27th to 28th - booth 2_32
        • Cloud Native London Meetup in London on August 2nd 

        • The Developer-First Security Week online from August 7 to 11th

        At the Cloud Native Meetup, our Product Lead, Alex Olivier, will be delivering a talk that you won't want to miss! Alex will likewise be presenting at the Developer-First Security Week on August 9th, at 1pm EST.

         

        Blog highlights

        Authorization remains #1 issue - OWASP 2023 Top 10 List

        Authorization remains the top issue in the OWASP Foundation 2023 Top 10 List. The top issue of 2023 is “Broken Object Level Authorization” - a specific form of Broken Access Control where unauthorized users can gain access to objects they shouldn't due to insufficient authorization checks at the object level.

         

        Discover how to ensure robust Object Level Authorization that aligns with the OWASP Top 10 recommendations.

        Nested fields support with Prisma Query Plans

        We are excited to share the latest improvements to Cerbos' Query Plan Adapter for Prisma, offering enhanced support for nested relation fields to be filtered by policy conditions. Cerbos Query Plans are the solution to filtering database query results based on what a user has permissions to access derived from policy. These are dynamically generated for every unique request making use of the context about the principal making the call and the resource type they are trying to access.

         

        Head over to our blog post for more details.

        Cerbos adds major new features to Cerbos Cloud

        The new features put together by our team are based on valuable feedback from our beta users. They are designed to further streamline workflows, and make the authorization management process of developers even more efficient and effective.

         

        Check out the new features being added, here.

         

        Stay connected:

        • Join our Slack Community to keep up-to-date with latest developments
        • Lets us help you build or review your first policy. Book a 30 minute free workshop
        • Cerbos core is open source, feel free to browse or contribute
        • Get started with Cerbos using our tutorial
        • Browse our developer documentation
        • Experience Cerbos and policy writing via an in-browser playground
        Twitter Twitter
        LinkedIn LinkedIn
        YouTube YouTube
        Email Email
        Custom Icon Product Hunt

        Cerbos, ABR, London, UK

        Unsubscribe Manage preferences