Last post May 15, 2012 03:26 PM by dbaier
Apr 26, 2012 01:14 PM|MasterV23|LINK
I'm trying to learn how I can authorize my web api calls so that when the call is made I can make sure it's being called from a valid site.
I've added the [Authorize] attribute to my API Contoller, what's the next step since these will be resful calls? Is there a key generator that I would need to use?
Apr 26, 2012 01:55 PM|dbaier|LINK
...and how would you identify a "valid site" ?
Apr 26, 2012 02:26 PM|aliostad|LINK
HTTPS calls can optionally have a client certificate which can be used by the clients.
A practical replacement is using username/password.
There is a Referer HTTP header in the request that can be checked (if it has been referred from another page/site) but you cannot really call it security. http://en.wikipedia.org/wiki/HTTP_referrer
Apr 26, 2012 02:36 PM|MasterV23|LINK
So for authticating Restful services wouldn't you want to try an encrypted key to verify? Just thinking out loud.
Apr 27, 2012 01:30 AM|MasterV23|LINK
Apr 27, 2012 06:09 AM|dbaier|LINK
Well - OAuth has a number of parts.
But if you are looking for a way to do token based authentication, I've written the necessary plumbing for that:
May 15, 2012 12:43 PM|MasterV23|LINK
So what is best to use? OAuth or Token?
Also I clicked the links at the bottom of that page but I got "Page Can Not be Found" error.
May 15, 2012 03:26 PM|dbaier|LINK
I moved my blog. The links are updated now.