awesome-repositories.com
Blog
MCP
awesome-repositories.com

Descubre los mejores repositorios open-source con nuestra búsqueda potenciada por IA.

ExplorarBúsquedas curadasAlternativas open-sourceSoftware autohospedableBlogMapa del sitio
ProyectoServidor MCPAcerca deCómo clasificamosPrensa
Aviso legalPrivacidadTérminos
© 2026 Bringes Technology SRL·VAT RO45896025·hello@awesome-repositories.com
·

74 repositorios

Awesome GitHub RepositoriesDomain-Based Access Controls

Security configurations that allow or restrict workspace access based on verified email domains.

Distinguishing note: Distinct from general user management: specifically handles automated provisioning based on organizational identity.

Explore 74 awesome GitHub repositories matching security & cryptography · Domain-Based Access Controls. Refine with filters or upvote what's useful.

Awesome Domain-Based Access Controls GitHub Repositories

Encuentra los mejores repositorios con IA.Buscaremos los repositorios que mejor coincidan usando IA.
  • twentyhq/twentyAvatar de twentyhq

    twentyhq/twenty

    50,113Ver en GitHub↗

    Twenty is a headless customer relationship management framework that enables developers to build, version, and deploy custom business applications using code. By utilizing a declarative approach to data modeling, the platform allows for the definition of custom objects, fields, and complex relationships directly within the source code. This schema-driven architecture automatically generates corresponding REST and GraphQL APIs, ensuring that data structures and interface components remain synchronized across development and production environments. The platform distinguishes itself through a m

    Allow users with specific email domains to automatically join your workspace without requiring individual invitations, simplifying the onboarding process for your entire organization.

    TypeScriptcrmcrm-systemcustomer
    Ver en GitHub↗50,113
  • netbirdio/netbirdAvatar de netbirdio

    netbirdio/netbird

    26,188Ver en GitHub↗

    NetBird is a zero-trust networking platform that builds secure, encrypted peer-to-peer overlay networks using the WireGuard protocol. It functions as a software-defined perimeter, connecting distributed infrastructure across cloud environments and physical locations while hiding network resources from the public internet. By integrating with external identity providers, the platform enforces granular access control and identity-based segmentation for every user and device. The platform distinguishes itself through extensive automation and programmatic management capabilities. It provides a ce

    Groups new users into organizations automatically based on email domains to simplify onboarding.

    Gogolangmeshmesh-networks
    Ver en GitHub↗26,188
  • activepieces/activepiecesAvatar de activepieces

    activepieces/activepieces

    20,887Ver en GitHub↗

    Activepieces is an open-source, self-hosted workflow automation platform designed to connect third-party applications through modular triggers and actions. It provides a low-code integration framework that allows users to build, manage, and execute complex business logic sequences within isolated, sandboxed environments. The platform distinguishes itself through its focus on embeddability and enterprise-grade security. It features an embedded automation builder that can be integrated into external applications via iframes, supported by comprehensive identity and access management tools such a

    Enforces domain-based SSO and restricts access to authorized organizational email domains.

    TypeScriptai-agentai-agent-toolsai-agents
    Ver en GitHub↗20,887
  • claude-code-best/claude-codeAvatar de claude-code-best

    claude-code-best/claude-code

    20,272Ver en GitHub↗

    Claude Code is a command-line interface and multi-agent orchestration framework designed for autonomous software engineering. It enables AI agents to perform codebase modifications, debugging, and Git workflow management while coordinating multiple specialized agents to decompose and execute complex engineering tasks in parallel. The system distinguishes itself through a high degree of isolation and safety, utilizing Git worktrees to create independent working directories for concurrent agents and implementing a tiered permission system that combines user rules, project policies, and OS-level

    Limits agent capabilities by whitelisting only specific tools allowed for a given skill or workflow.

    TypeScript
    Ver en GitHub↗20,272
  • casbin/casbinAvatar de casbin

    casbin/casbin

    19,848Ver en GitHub↗

    Casbin is an authorization library that provides a model-based engine for enforcing access control across diverse application environments. It decouples authorization logic from application code by using a configuration-driven approach, allowing developers to define access rules and evaluation logic independently. The system supports a wide range of access control models, including role-based, attribute-based, and relationship-based patterns, which are evaluated at runtime to determine if a subject is permitted to perform an action on a resource. The project distinguishes itself through a hig

    Enables domain-scoped permission management to control access across multi-tenant environments.

    Goabacaccess-controlacl
    Ver en GitHub↗19,848
  • nondanee/unblockneteasemusicAvatar de nondanee

    nondanee/UnblockNeteaseMusic

    17,387Ver en GitHub↗

    UnblockNeteaseMusic is a network gateway and proxy server designed to restore playback for unavailable songs on Netease Cloud Music. It functions as an HTTP traffic proxy that intercepts requests to unlock restricted digital content and bypass regional availability limits. The project acts as a regional content gateway, using custom IP parameters and request rerouting to bypass geographic blocks. It restores access to restricted tracks by diverting network traffic from official servers to alternative music sources. The server manages network traffic routing through domain-based routing and U

    Includes a whitelist-based filter to restrict proxy usage to approved domains and prevent unauthorized server access.

    JavaScriptnetease-cloud-musicproxy-serverunblocker
    Ver en GitHub↗17,387
  • tencent/weknoraAvatar de Tencent

    Tencent/WeKnora

    16,974Ver en GitHub↗

    WeKnora is a multi-tenant retrieval-augmented generation (RAG) knowledge platform and autonomous AI agent framework. It transforms raw documents into queryable knowledge bases and integrates large language models with vector databases to provide grounded AI responses. The system also functions as a Model Context Protocol (MCP) tool server, exposing knowledge search and agentic capabilities to external AI clients. The platform distinguishes itself through an autonomous agent framework that utilizes iterative reasoning, tool calling, and web search to solve multi-step tasks. It implements a sta

    Defines trusted domains and IP addresses to bypass security restrictions during validation.

    Goagentagenticai
    Ver en GitHub↗16,974
  • h2y/shadowrocket-adblock-rulesAvatar de h2y

    h2y/Shadowrocket-ADBlock-Rules

    16,653Ver en GitHub↗

    This project provides predefined configuration profiles and rule sets for ad filtering, geographic traffic steering, and proxy routing. It specifically offers curated rule sets and configuration lists for Shadowrocket to filter advertising domains and manage network traffic on iOS devices. The project specializes in converting industry-standard ad-blocking filter lists into a proprietary rule format compatible with proxy client configurations. These rule sets facilitate the separation of domestic and foreign network requests to optimize connection paths and bypass regional restrictions. The

    Routes all traffic directly by default while forwarding only specific approved domains through a proxy server.

    Pythongfwproxyshadowrocket
    Ver en GitHub↗16,653
  • quarkusio/quarkusAvatar de quarkusio

    quarkusio/quarkus

    15,479Ver en GitHub↗

    Quarkus is a Kubernetes-native Java framework designed for building high-performance, memory-efficient applications. It utilizes ahead-of-time native compilation to transform Java code into standalone, optimized binaries that eliminate the need for a virtual machine, enabling rapid startup and reduced memory consumption. By performing code augmentation during the build phase, it shifts heavy processing tasks away from runtime, ensuring that applications are optimized for cloud-native environments. The framework distinguishes itself through a unified approach to reactive and imperative program

    Integrates authentication realms and security domains to enforce access control policies across the application.

    Javacloud-nativehacktoberfestjava
    Ver en GitHub↗15,479
  • projectdiscovery/subfinderAvatar de projectdiscovery

    projectdiscovery/subfinder

    13,105Ver en GitHub↗

    Subfinder is a security reconnaissance framework designed for subdomain enumeration and attack surface management. It functions as a discovery engine that identifies and maps internet-exposed infrastructure, cloud-hosted assets, and network ranges to maintain a comprehensive inventory of an organization's digital footprint. The project distinguishes itself through a modular, template-driven scanning engine that executes security checks against discovered assets. It leverages cloud-native asset discovery to query provider APIs and infrastructure metadata, while supporting distributed agent orc

    Restricts platform access to verified organizational domains and mandates single sign-on.

    Gobugbountyhackinghacktoberfest
    Ver en GitHub↗13,105
  • zitadel/zitadelAvatar de zitadel

    zitadel/zitadel

    13,029Ver en GitHub↗

    This project is a cloud-native identity and access management platform designed to centralize authentication, authorization, and identity lifecycle management. It functions as a standards-compliant OpenID Connect authorization server, providing secure session management and token issuance for web, mobile, and device-based applications. The platform is built to handle complex identity requirements through stateless token authentication and support for modern passwordless methods, including biometrics and hardware keys. What distinguishes this platform is its native support for multi-tenant env

    Directs users to specific organization login policies based on the domain suffix of their email address.

    Go2faauthenticationauthorization
    Ver en GitHub↗13,029
  • spatie/laravel-permissionAvatar de spatie

    spatie/laravel-permission

    12,911Ver en GitHub↗

    This is a role-based access control system for Laravel applications that manages user permissions and roles within a database. It provides a database permissions manager to assign specific abilities to users and roles, utilizing authorization gates to restrict access to routes and interface elements. The project features a wildcard permission system that uses pattern matching to grant broad access across multiple related permissions. It also supports team-scoped access control, allowing users to maintain different roles and permission levels across separate organizational contexts or teams.

    Supports multi-tenant scoping so that roles and permissions are isolated within specific organizational teams.

    PHP
    Ver en GitHub↗12,911
  • hotchemi/permissionsdispatcherAvatar de hotchemi

    hotchemi/PermissionsDispatcher

    11,177Ver en GitHub↗

    PermissionsDispatcher es una biblioteca declarativa para la gestión de permisos en Android. Proporciona un framework para manejar permisos en tiempo de ejecución y permisos especiales mediante una API que dirige los resultados de las solicitudes a métodos manejadores específicos. La biblioteca utiliza anotaciones para activar métodos designados para casos de éxito, justificaciones o denegaciones. Coordina tanto los flujos estándar de permisos en tiempo de ejecución como los permisos especializados que requieren dirigir al usuario a la configuración del sistema para su aprobación manual. El sistema incluye flujos de trabajo para justificaciones de permisos personalizadas y manejo de denegaciones, incluyendo alternativas para cuando los usuarios seleccionan la opción de no volver a preguntar. También cuenta con filtrado de versiones de SDK para restringir las solicitudes de permisos según el nivel máximo de API.

    Provides a declarative model for mapping runtime permission results to corresponding handler methods.

    Java
    Ver en GitHub↗11,177
  • thumbor/thumborAvatar de thumbor

    thumbor/thumbor

    10,501Ver en GitHub↗

    Thumbor is a dynamic image processing service and proxy server that resizes, crops, and filters images on demand via URL parameters. It functions as a URL-based image manipulator that generates specific image versions from source assets to optimize web delivery. The system includes a smart cropping engine that uses facial feature detection and computer vision to automatically center thumbnails on the most relevant visual content. To prevent unauthorized parameter tampering and malicious requests, it employs signature-based request validation and domain-based source whitelisting. Broad capabi

    Implements a whitelist of trusted external domains to restrict where source images are fetched from.

    Pythonhacktoberfest
    Ver en GitHub↗10,501
  • privacy-protection-tools/anti-adAvatar de privacy-protection-tools

    privacy-protection-tools/anti-AD

    10,156Ver en GitHub↗

    This project is an ad-blocking filter list and DNS blocklist collection designed to prevent advertisement and tracking servers from loading content across devices. It functions as a network-layer ad filter by providing a curated set of domain patterns and URLs that network components use to block known advertising and big data statistics domains. The collection focuses on privacy-focused domain filtering to stop the unauthorized collection of personal information and user tracking. It identifies and blocks domains associated with telemetry, analytics, and log collection to prevent the upload

    Maintains curated lists of domain names and patterns to prevent requests to known advertising servers.

    adblockadguardhomednsmasq
    Ver en GitHub↗10,156
  • elie222/inbox-zeroAvatar de elie222

    elie222/inbox-zero

    10,101Ver en GitHub↗

    Inbox Zero is an AI-powered email automation platform and inbox organizer. It uses large language models to automatically categorize, label, and archive emails, while providing a conversational interface for managing workflows and drafting responses through natural language. The project distinguishes itself by integrating real-time calendar availability into its drafting process and generating AI-summarized meeting briefings. It supports a pluggable AI provider interface with model fallback chains, allowing it to connect to various cloud or local LLM providers. Users can also control their in

    The product limits new account creation to specific email addresses or authorized domains to control access.

    TypeScriptaiemailgmail
    Ver en GitHub↗10,101
  • samratashok/nishangAvatar de samratashok

    samratashok/nishang

    9,951Ver en GitHub↗

    Nishang is a PowerShell-based offensive security framework designed for red teaming and penetration testing on Windows targets. It functions as a post-exploitation toolkit and payload generator to automate attacks and manage remote targets. The project provides specialized capabilities for bypassing security controls, such as disabling the Antimalware Scan Interface and employing in-memory execution to avoid disk-based detection. It includes a variety of stealthy command and control mechanisms, utilizing non-standard channels like DNS TXT records, ICMP traffic, and webmail for communication a

    The tool adjusts access control lists on a domain controller to enable directory database shadow copies.

    PowerShellactivedirectoryhackinginfosec
    Ver en GitHub↗9,951
  • rob--w/cors-anywhereAvatar de Rob--W

    Rob--W/cors-anywhere

    9,347Ver en GitHub↗

    This project is a Node.js HTTP proxy server that enables cross-domain API requests from browsers by injecting Cross-Origin Resource Sharing headers into HTTP responses. It functions as a reverse proxy gateway and header manipulator, allowing for the interception and modification of traffic between a client and a target server. The proxy provides mechanisms to bypass browser same-origin policy restrictions through automated header injection. It includes capabilities for origin-based rate limiting and request interception to control traffic flow and prevent unauthorized usage of the proxy servi

    Controls access to the target server using whitelists and blacklists of originating domains.

    JavaScript
    Ver en GitHub↗9,347
  • kenshin/simpreadAvatar de Kenshin

    Kenshin/simpread

    8,650Ver en GitHub↗

    Simpread is a browser extension that transforms any web page into a clean, distraction-free reading layout optimized for comfortable reading and annotation. It functions as both a reading mode tool and a read-later service, allowing users to save pages for offline or future access while marking up text with highlights and notes. The extension distinguishes itself through deep integration with note-taking and productivity platforms, enabling direct export of annotations and cleaned pages to Obsidian, Logseq, Roam Research, Notion, and other tools. It also supports sending articles to Instapape

    Enters reading mode automatically only for sites on a user-defined whitelist for more control than a blacklist alone.

    JavaScriptchromechrome-extensioncrx
    Ver en GitHub↗8,650
  • lolbas-project/lolbasAvatar de LOLBAS-Project

    LOLBAS-Project/LOLBAS

    8,323Ver en GitHub↗

    LOLBAS is a curated database and knowledge base of signed Windows binaries that can be misused to bypass security restrictions and execute unauthorized code. It serves as a technical registry that maps trusted system files to their functional capabilities and the offensive tactics they enable. The project distinguishes itself by providing a capability-driven indexing system and a tactics registry that relates legitimate binary functionality to known security evasion techniques. It includes an association layer that links specific system binaries to attack patterns and tactical objectives, pro

    Extracts sensitive directory information by manipulating permissions to facilitate volume shadow copy extraction of the NTDS.dit database.

    XSLTblueteamdfirliving-off-the-land
    Ver en GitHub↗8,323
Ant.123…4Siguiente
  1. Home
  2. Security & Cryptography
  3. Domain-Based Access Controls

Explorar subetiquetas

  • Domain Name Blocking12 sub-etiquetasPreventing the resolution of specific domain names using blocklists or custom zones. **Distinct from Domain Whitelists:** Focuses on blocking resolution entirely, whereas whitelists specifically permit known traffic.
  • Domain Whitelists5 sub-etiquetasAccess control mechanisms that permit traffic only from a predefined list of approved domains. **Distinct from Domain-Based Access Controls:** Focuses specifically on whitelisting approved domains for proxy access, rather than organizational identity provisioning.
  • Domain-Scoped Permissions3 sub-etiquetasManagement of user roles and permissions within specific organizational domains or tenants. **Distinct from Domain-Based Access Controls:** Distinct from general domain-based access controls: focuses on granular permission assignment rather than just traffic validation.
  • Organizational Data SegmentationHierarchical data partitioning to enforce administrative boundaries and access controls within an organization. **Distinct from Domain-Based Access Controls:** Focuses on data folder hierarchy for GRC governance rather than identity-based email domain filtering.
  • Script Execution BlockingPrevents specific scripts from executing on designated domains using blacklists. **Distinct from Domain-Based Access Controls:** Focuses on blocking JavaScript execution within the browser page rather than restricting workspace access or DNS resolution
  • Security Realms1 sub-etiquetaIntegrates authentication realms and security domains to enforce access control policies. **Distinct from Domain-Based Access Controls:** Distinct from Domain-Based Access Controls: focuses on the internal application security domain/realm structure rather than email-domain-based access.
  • User-Agent and Domain BlockingPrevents connectivity to services by filtering requests based on hostnames, suffixes, or user-agent strings. **Distinct from Domain Name Blocking:** Combines domain blocking with user-agent identification for more granular request rejection.