Re: Tracking client-applications using User-Agent
Jan Algermissen <[email protected]>
| Newsgroups | gmane.comp.web.services.rest |
|---|---|
| Message-ID | <[email protected]> |
On 03.04.2013, at 10:52, Mike Kelly <[email protected]> wrote: > If the request hits a cache your origin server isn't going to see the request so how would that work? Ha! Classic facepalm.org . (Should say it was just a trick question...) Let's assume I control the cache because it is inside a large corporation. Yeah - I could offload the auth at that point, too. I know... Still curious. Jan > > I think I would just stick to doing auth via the auth header. But I might be missing something? > > Cheers, > M > > On 3 Apr 2013 09:46, "Jan Algermissen" <[email protected]> wrote: > > Hi, > > suppose, you expose a REST-API and want to keep track clients which you gave access to the API. Each client is given a client ID. > > Straight-forward solution would be to use the Authentication (think OAuth) header to extract the client ID. > > However, suppose there are some resource you do not want to protect to enable public caching. > > What about asking the client developers to put the client ID in the User-Agent header. Yes, they would not have to, but let's suppose they are closely enough associated to be reliable enough. If this occasionally slips, that's no big deal. It is for monitoring purposes only. No payment-per-ID or throttling involved. > > Do you have any thoughts or experiences doing something similar? > > Jan > > ------------------------------------ Yahoo! Groups Links <*> To visit your group on the web, go to: http://groups.yahoo.com/group/rest-discuss/ <*> Your email settings: Individual Email | Traditional <*> To change settings online go to: http://groups.yahoo.com/group/rest-discuss/join (Yahoo! ID required) <*> To change settings via email: [email protected] [email protected] <*> To unsubscribe from this group, send an email to: [email protected] <*> Your use of Yahoo! Groups is subject to: http://docs.yahoo.com/info/terms/