Skip to main content

Posts

Showing posts with the label Token

Manage bearer token when we scale on more than one server - OWIN, Katana, AngularJS

In this post we will talk about bearer token authentication and how we should manage this token when our application is running on more than one server -  when we are using OWIN, Katana and AngularJS. Token Characteristics First of all let’s see what are the characteristics of bearer token: Generate by server Contains user claims (what kind of operations a user can do/roles) All information that a token contains are encrypted Token information can be decrypted only by the machine that created the token Expiration date is encrypted in the token itself No token information are stored on the server side Encryption is safe enough to be used worldwide (Facebook, Google and Twitter are using it)  A token can be used by external system only when decryption key is shared Easy and cheap to generate tokens Why? All this sounds good, but what is happening if we want to go in production. In this case we should be able to scale our backend from one node to 3 or 10 nodes. D...

Mecanisme de autentificare: Security Token Service(STS) si Web Service Federation( WSF)

In momentul de fata aproape pe fiecare portal găsim mecanisme prin care putem să ne logam cu contul de Facebook, Y!, Google sau să facem anumite operațiuni folosind aceste conturi. Toate aceste funcționalități sunt oferite prin mecanisme gen Security Token Service (STS). STS a fost introdus de către Microsoft in 2005, in acest moment este folosit peste tot, inclusiv in aplicațiile din cloud( Windows Azure). Pe baza unui singur cont pe un anumit domeniu putem să accesam și să folosim n domenii pe baza unui singur cont. Pattern-ul de baza se numeste Brokered Authentication. Exista 3 jucători principali: clientul - care dorește sa acceseze un anumit domeniu; STS - serviciul care validează credențialele; Serviciul( domeniul) - pe care un client vrea să îl acceseze; Principiul de baza care sta la baza STS este următorul: clientul trimite o cerere de autentificare la STS( un mesaj cunoscut sub numele de Request Security Token ( RST)); STS verifica credentialele și trimite un mesaj de confirm...