Uploaded image for project: 'apiman (API Management)'
  1. apiman (API Management)
  2. APIMAN-177

Improved security for auth-token auth

    XMLWordPrintable

Details

    Description

      The auth-token support (used in the community edition currently) can easily be made more secure. It requires a shared secret between the UI and the API. This shared secret could be generated once and stored in a simple persistent ISPN cache. It would make it impossible for auth tokens to be forged.

      Attachments

        Activity

          People

            ewittman@redhat.com Eric Wittmann
            ewittman@redhat.com Eric Wittmann
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: