Sabitlenmiş Tweet
Maxwell
17 posts

Maxwell
@mvxvvll
Building @WorkOS | Co-founder @ConnectReportHQ | Security + Enterprise
New York, NY Katılım Eylül 2011
174 Takip Edilen382 Takipçiler

@npmjs @GHSecurityLab Pin axios at v1.14.0 - this version is safe
If you think you’ve been compromised - rotate your GH, NPM, and any keys available in any environments where you updated this package. The compromised package ran a script that called out to a remote C&C service
English

Ok I managed to make the code generated interactive so every idea is really becoming an app now
Obvious next question, why not just generate every idea automatically and add Stripe to it and launch them?
@levelsio@levelsio
✨ Every idea on ideasai.com now also generates an app because just a landing page isn't enough of course In the fake Chrome browser you can switch [ Landing | App ] And download both mock ups to build it further
English
Maxwell retweetledi

Had the chance to connect with @chantastic about shipping embedded code editors in 2025, and how we approached this at @WorkOS to power JWT templates for @authkit.
WorkOS@WorkOS
WorkOS Launch Week - Day 3 { Custom Objects } WorkOS now gives you even more control over user, org, and session attributes with three powerful new features: 🗂️ Add Custom Metadata to users and organizations 🆔 Use your own External ID to fetch users and orgs 📜 Utilize Custom JWT Templates to augment session tokens with any JSON attributes and values Listen in as @chantastic and Maxwell Hammad deep dive into the capabilities!
English
Maxwell retweetledi

🚨 Security Alert 🚨
WorkOS is disclosing a critical SAML authentication bypass in xml-crypto and Node.js libraries.
This flaw allows attackers to forge SAML responses, potentially granting unauthorized access to any user account in affected applications—including admin accounts—without any user interaction. This enables full account takeovers.
WorkOS customers are safe and were not impacted.
Any service using xml-crypto or a Node.js SAML implementation using it should update immediately to the latest version.
Full blog post with technical details 👇

English

@levelsio There is always one guy on a call. Tried many co-working spaces and the reason I left was mainly cause of this.
English

@dr low-touch customers don't owe you an explanation, unfortunately.
in the US, the FTC recently decided co's must provide a cancellation mechanism, "at least as easy to use as the method the customer used to buy the product or service in the first place."
niemanlab.org/2021/11/the-en…
English

@AnTheMaker I've generally had success with SES or Gmail servers, unless the destination is a super restrictive corporate inbox.
English

@csallen have ya tried liquidti.me? it has pretty good visualizations; sometimes a little buggy since it's very new but worth it
English

@nycbabylon congrats on getting #beaumoji on #producthunt! i developed the site with color + information, could you add me as a maker? 🙏🏼
English










