Re: Security

Jan Algermissen <[email protected]>
Newsgroups gmane.comp.web.services.rest
Message-ID <[email protected]>
Hi Mohan,

On 21.04.2013, at 04:08, Mohan Radhakrishnan <[email protected]> wrote:

> 
> Hi,
> 
> What are the recommendations for securing REST calls ?

I recommend OAuth1[1] 2-legged[2] for now and I recommend watching Oz[3] which, among other things, solves the scalability issues of OAuth1.

Jan


[1] http://tools.ietf.org/html/rfc5849
[2] http://oauth.googlecode.com/svn/spec/ext/consumer_request/1.0/drafts/1/spec.html
[3] https://github.com/hueniverse/oz



> I searched and found http://answers.oreilly.com/topic/2180-rest-in-practice-http-security-essentials/
> 
> So what I understand is that when people say that REST does not have security they are probably thinking of WS-Security. I am not contrasting SOAP with REST here but just trying to get various ideas for REST HTTP protocol security. I understand HTTPS is separate.
> 
> Thanks,
> Mohan
> 
> 



------------------------------------

Yahoo! Groups Links

<*> To visit your group on the web, go to:
    http://groups.yahoo.com/group/rest-discuss/

<*> Your email settings:
    Individual Email | Traditional

<*> To change settings online go to:
    http://groups.yahoo.com/group/rest-discuss/join
    (Yahoo! ID required)

<*> To change settings via email:
    [email protected] 
    [email protected]

<*> To unsubscribe from this group, send an email to:
    [email protected]

<*> Your use of Yahoo! Groups is subject to:
    http://docs.yahoo.com/info/terms/
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.