Uploaded image for project: 'apiman (API Management)'
  1. apiman (API Management)
  2. APIMAN-177

Improved security for auth-token auth

XMLWordPrintable

      The auth-token support (used in the community edition currently) can easily be made more secure. It requires a shared secret between the UI and the API. This shared secret could be generated once and stored in a simple persistent ISPN cache. It would make it impossible for auth tokens to be forged.

              ewittman@redhat.com Eric Wittmann
              ewittman@redhat.com Eric Wittmann
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: