Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Diskutere autentisering #13

Open
danmichaelo opened this issue Jun 29, 2015 · 1 comment
Open

Diskutere autentisering #13

danmichaelo opened this issue Jun 29, 2015 · 1 comment
Labels

Comments

@danmichaelo
Copy link
Member

Utfordring: Vi kan ikke lagre en API-nøkkel sikkert i en JS-klient. Vi kan heller ikke basere oss på at IP stemmer (ved IP-spoofing vil ikke klienten motta responsen (tror jeg), men en POST-forespørsel kan jo uansett ha fått utført skade).

Men vi kan kanskje bruke IP-basert autentisering hvis vi kombinerer det med token.. F.eks,. Klient sier "hei", får redigeringstoken tilbake basert på IP-adresse. Deretter kan klienten gjøre POST-forespørsler så lenge den sender med tokenet.

JSON web tokens ser veldig interessant ut.

@danmichaelo
Copy link
Member Author

reminder to self: https://github.com/tymondesigns/jwt-auth

danmichaelo added a commit that referenced this issue Jun 29, 2015
Won't work for requests from outside Laravel
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

1 participant