3 ms·
1) What would your recommendation be if it's not only an API but an ensemble of services that need authentication and authorization? It's feasible to use signed
by lsb 11y ago
1) What would your recommendation be if it's not only an API but an ensemble of services that need authentication and authorization? It's feasible to use signed (and maybe encrypted) JWTs for such a purpose, but it'd be interesting to hear your thoughts.
2) To avoid this sort of repeated question, do you have a set of guidelines to avoid common mistakes and generally Do The Right Thing for standard security problems?
- breischl 11y agoThis is a little more crypto-oriented, but might be along the lines of what you're looking for. https://gist.github.com/tqbf/be58d2d39690c3b366ad https://gist.github.com/tqbf/be58d2d39690c3b366ad