4 ms·
If the authors are reading this: in your later articles, I'd love to see some details about what method of authentication and authorization you settled on for t
by matrix 11y ago
If the authors are reading this: in your later articles, I'd love to see some details about what method of authentication and authorization you settled on for the REST API and how well it plays with Dropwizard.
- necubi 11y agoYeah, I think authentication and authorization are two of the hardest challenges in moving to a fully static app architecture. There're some more details in a talk I gave a few months ago (video: https://youtu.be/vHXcDKK4eGY?t=6822 https://youtu.be/vHXcDKK4eGY?t=6822, slides: https://www.dropbox.com/s/uup4tgxyi7uybe0/API-Driven%20Development%20at%20Sift%20Science.pdf?dl=0 https://www.dropbox.com/s/uup4tgxyi7uybe0/API-Driven%20Devel...), and I'll be writing more (and hopefully open sourcing some code) in the future. The upshot is we settled on OAuth 2.0 with JWT auth tokens, along with some custom DropWizard filters and annotations to enforce authz. We found two-legged OAuth 2.0 pretty straightforward to implement and use.
- matrix 11y agoSounds like you guys might have used Apache Oltu? If so, I (and I'm sure many others) would be interested in hearing more about that, because modern, non-trivial authorization and authentication is probably the single biggest missing piece for Jersey/Dropwizard.