Skip to Content
API Security in Action
book

API Security in Action

by Neil Madden
January 2021
Intermediate to advanced
576 pages
18h 9m
English
Manning Publications
Content preview from API Security in Action

3 Securing the Natter API

This chapter covers

  • Authenticating users with HTTP Basic authentication
  • Authorizing requests with access control lists
  • Ensuring accountability through audit logging
  • Mitigating denial of service attacks with rate-limiting

In the last chapter you learned how to develop the functionality of your API while avoiding common security flaws. In this chapter you’ll go beyond basic functionality and see how proactive security mechanisms can be added to your API to ensure all requests are from genuine users and properly authorized. You’ll protect the Natter API that you developed in chapter 2, applying effective password authentication using Scrypt, locking down communications with HTTPS, and preventing denial of service attacks ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Advanced API Security: OAuth 2.0 and Beyond

Advanced API Security: OAuth 2.0 and Beyond

Prabath Siriwardena
Logging in Action

Logging in Action

Phil Wilkins

Publisher Resources

ISBN: 9781617296024Supplemental ContentPublisher SupportOtherPublisher WebsiteSupplemental ContentPurchase Link