Skip to main content

Posts

Showing posts with the label authentification

OWIN, OAuth - Bearer tokens: Authentication and Authorization for unit tests

It is a fact that nowadays, SPA applications are used in almost all new web project. In general behind a SPA application we have multiple REST endpoints that are used to get data, execute different actions and many more. Token base authentication is worldwide use when we need to secure a REST endpoint and offer a mechanism for authentication and authorization. In general when we create a SPA application using AngularJS we will use token based authentication. This mean that we will have an endpoint called ‘token’ (or other path) where users can send their username and password and receive a token that can be used to access different resources. Once we have the token, we will set the bearer token value of the authorization heather. Beside this we need to be able to write unit tests or integration tests that hit our REST services and validate their functionality. For this purpose we need to have a code that simulates the authentication step and inject in the REST request th...

Mecanisme de autentificare: Security Token Service(STS) si Web Service Federation( WSF)

In momentul de fata aproape pe fiecare portal găsim mecanisme prin care putem să ne logam cu contul de Facebook, Y!, Google sau să facem anumite operațiuni folosind aceste conturi. Toate aceste funcționalități sunt oferite prin mecanisme gen Security Token Service (STS). STS a fost introdus de către Microsoft in 2005, in acest moment este folosit peste tot, inclusiv in aplicațiile din cloud( Windows Azure). Pe baza unui singur cont pe un anumit domeniu putem să accesam și să folosim n domenii pe baza unui singur cont. Pattern-ul de baza se numeste Brokered Authentication. Exista 3 jucători principali: clientul - care dorește sa acceseze un anumit domeniu; STS - serviciul care validează credențialele; Serviciul( domeniul) - pe care un client vrea să îl acceseze; Principiul de baza care sta la baza STS este următorul: clientul trimite o cerere de autentificare la STS( un mesaj cunoscut sub numele de Request Security Token ( RST)); STS verifica credentialele și trimite un mesaj de confirm...