7 ms·
I've chased the RESTful login/authentication around the web off and on when thinking about REST apis. It seems to boil down to two main approaches. 1 - follow
by tom_b 14y ago
I've chased the RESTful login/authentication around the web off and on when thinking about REST apis. It seems to boil down to two main approaches.
1 - follow the AWS API models, with a signed request using a private secret known only to the user and the server-side. You can see the S3 docs on RESTful auth using this approach. Also seems to recommend doing this over SSL.
2 - use SSL and send a userid/passwd or authentication key on each request.
In general, cookies are regarded as one of those "makes it not restful" type things.
I'd love to hear from HN'ers on how they handle RESTful authentication, particularly for projects where they are providing an API that is primarily consumed by a web app or other tool they implemented for users and have used RESTful api design as a design viewpoint.
- philjackson 14y agoApiAxle provides the first method with a hmac sha1 encoding of the current epoch, secret key and api key. http://apiaxle.com/docs/signing-requests/ http://apiaxle.com/docs/signing-requests/