Interested to understand why the unconditional ban on API Keys for auth. When one party is both the Auth and Resource Server (which is rather frequent) or conversely if someone is both the client+user, what's the problem with API Keys? (i.e. 2-Legged client_id+client_secret)
-
-
-
Great question! API keys are not designed for user authentication and they lack important security mechanisms, such as expiration. They are like passwords in some way and different components might store them (logs, proxies)https://cloud.google.com/endpoints/docs/openapi/when-why-api-key …
Kraj razgovora
Novi razgovor -
-
-
Massive contribution to the APISec practice. Cheers.
#appsec#apisec#api#devsecopsHvala. Twitter će to iskoristiti za poboljšanje vaše vremenske crte. PoništiPoništi
-
Čini se da učitavanje traje već neko vrijeme.
Twitter je možda preopterećen ili ima kratkotrajnih poteškoća u radu. Pokušajte ponovno ili potražite dodatne informacije u odjeljku Status Twittera.