3 ms·
I've been mulling the idea of SOA-on-heroku lately - I'm used to working with SOA where the web service is publicly exposed, and the services are all available
by alook 14y ago
I've been mulling the idea of SOA-on-heroku lately - I'm used to working with SOA where the web service is publicly exposed, and the services are all available only on the intranet.
This brings up bigger questions with regards to authentication - how does the 'api' service know that a request is coming from a correctly authenticated user? Since on heroku, the 'api' service would be externally exposed, I'm trying to decide if there's a good way to correctly authenticate/authorize in such a way that the 'api' service understands.
Thoughts?
- rdegges 14y agoI do this via HTTP Basic auth + ssl. On Heroku you get SSL for free (https://myapp.herokuapp.com https://myapp.herokuapp.com), so that + basicauth works pretty well. EDIT: Wanted to add that I love doing it on Heroku as you get the automatic load balancing so you can easily add web dynos.
- cmwelsh 14y agoYou can sign your messages using HMAC[1]. That's what Facebook does when it makes HTTP requests to your application. [1] http://rc3.org/2011/12/02/using-hmac-to-authenticate-web-service-requests/ http://rc3.org/2011/12/02/using-hmac-to-authenticate-web-ser...