【问题标题】:Rest Authentication - Token validation with a database look up Vs alternativesRest Authentication - 使用数据库查找的令牌验证与替代方案
【发布时间】:2015-09-30 15:48:26
【问题描述】:

我阅读了有关 stackoverflow 的几个问答,以实现 rest 身份验证。在其中一个问题中也找到了示例代码。 https://github.com/philipsorst/angular-rest-springsecurity/blob/master/src/main/java/net/dontdrinkandroot/example/angularrestspringsecurity/rest/AuthenticationTokenProcessingFilter.java

大多数答案都谈到了使用拦截器并根据身份验证标头(令牌和用户 ID 或登录 ID)过滤每个请求,并将其与存储在数据库中的请求进行比较。

我正在实施一个订单管理系统。 我的网址看起来像http://myapi.com/customers/{customerId}/Orders/{OrderId}

目前是http,我们即将设置https。

在 URL 中,我获得了客户 ID 和订单 ID。我使用订单 ID 和客户 ID 在数据库中快速查找,如果它返回一些行,我返回一个 JSON。

我的问题:

  1. 为了保护这个端点,我可以有一个安全拦截器。但是每次我都必须针对数据库验证请求。我有哪些替代方案(缓存?)来验证或授权每个请求?

  2. 这个休息端点被一个 android 应用程序(angular js)客户端和一个网站(一个 php 客户端)使用。对于移动设备,我不应该在每次用户登录时重新生成令牌。所以我将令牌有效期配置为 30 天。但是对于网站来说,它是一个会话令牌。应该如何处理这种情况?

【问题讨论】:

    标签: java rest spring-security token endpoint


    【解决方案1】:

    您需要的可以通过Oauth解决。

    您的后端 (REST-API) 将需要对您的 API 操作进行身份验证的访问权限。反过来,您的客户端/前端将需要在与后端通信时发出经过身份验证的请求。这是通过发送access tokens 来实现的。

    虽然这看起来很复杂,但看看Stormpath 对您来说非常有用。我们有一个非常简单的解决方案。请查看Using Stormpath for API Authentication。

    总而言之,您的解决方案将如下所示:

    1. 您将使用Stormpath Java SDK 轻松委派您的所有用户管理需求。
    2. 在您的前端,当用户按下登录按钮时,您的前端将通过其 REST API 将凭据安全地发送到您的后端。

      2.1。顺便说一句,Stormpath 极大地增强了这里的所有可能性。除了拥有自己的登录页面,您还可以通过 IDSite 将登录/注册功能完全委托给 Stormpath,或者您也可以将其委托给我们的 Servlet Plugin。 Stormpath 还支持 Google、Facebook、LinkedIn 和 Github 登录。

    3. 然后,您的后端将尝试根据 Stormpath 后端对用户进行身份验证,结果将返回 access token:

      /** This code will throw an Exception if the authentication fails */
      public void postOAuthToken(HttpServletRequest request, HttpServletResponse response) {
          Application application = client.getResource(applicationRestUrl, Application.class);
      
          //Getting the authentication result
          AccessTokenResult result = (AccessTokenResult) application.authenticateApiRequest(request);
      
          //Here you can get all the user data stored in Stormpath
          Account account = accessTokenResult.getAccount();
      
          response.setStatus(HttpServletResponse.SC_OK);
          response.setContentType("application/json");
      
          //Output the json of the Access Token
          response.getWriter().print(token.toJson());
          response.getWriter().flush();
      }
      
    4. 然后,对于每个经过身份验证的请求,您的后端都会这样做:

      /** This is your (now protected) exposed operation */ 
      public void getOrder(HttpServletRequest request, HttpServletResponse response) {
          Application application = client.getResource(applicationRestUrl, Application.class);
      
          OauthAuthenticationResult result = (OauthAuthenticationResult) application.authenticateOauthRequest(request).execute();
      
          System.out.println(result.getApiKey());
          System.out.println(result.getAccount());
      
          //Return what you need to return in the response
          doGetOrder(request, response);
      }
      

    请查看here了解更多信息

    希望有帮助!

    免责声明,我是 Stormpath 的活跃贡献者。

    【讨论】:

      猜你喜欢
      • 1970-01-01
      • 2018-03-24
      • 2023-03-29
      • 1970-01-01
      • 2011-09-04
      • 2019-09-08
      • 2014-02-24
      • 1970-01-01
      • 2018-01-30
      相关资源
      最近更新 更多