Uploaded image for project: 'eZ Publish / Platform'
  1. eZ Publish / Platform
  2. EZP-22495

implement WSSE authentication for REST API clients as alternative to plain session cookie + CSRF token

    XMLWordPrintable

Details

    • Icon: Feature Feature
    • Resolution: Obsolete
    • Icon: High High
    • None
    • None
    • None
    • None

    Description

      The "session-cookie plus CSRF-token" thing for API as currently implemented might be overhauled (either replaced or improved) by usage of WSSE:

      I am not 100% sure that the 2 technologies cover the exact same aspects.
      Probably for best ever protection, they should be combined.

      Maybe we could implement WSSE with the following improvement: the "secret" to be used for hashing nonces is the CSRF token.

      And voilĂ , 5 stars in API security

      Attachments

        Activity

          People

            Unassigned Unassigned
            gaetano.giunta-obsolete@ez.no Gaetano Giunta (Inactive)
            Votes:
            0 Vote for this issue
            Watchers:
            1 Start watching this issue

            Dates

              Created:
              Updated:
              Resolved: