Quantcast
Channel: SCN: Message List
Viewing all articles
Browse latest Browse all 9069

Re: Logon authentication in REST web service

$
0
0

Hi.

Do not send a username password combination but a username hash(username:password) combination, also work with hashvalues in your backend not with passwords saved anywhere.

Passwords should never be send over the network and should neither be stored.

The http get parameters are also secured via https, so as long as your ssl connection is not compromised it is no problem to transfer them in  a "fat url".

 

Best regards

 

Roland


Viewing all articles
Browse latest Browse all 9069

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>