Skip to Content
API Security in Action
book

API Security in Action

by Neil Madden
January 2021
Intermediate to advanced
576 pages
18h 9m
English
Manning Publications
Content preview from API Security in Action

5 Modern token-based authentication

This chapter covers

  • Supporting cross-domain web clients with CORS
  • Storing tokens using the Web Storage API
  • The standard Bearer HTTP authentication scheme for tokens
  • Hardening database token storage

With the addition of session cookie support, the Natter UI has become a slicker user experience, driving adoption of your platform. Marketing has bought a new domain name, nat.tr, in a doomed bid to appeal to younger users. They are insisting that logins should work across both the old and new domains, but your CSRF protections prevent the session cookies being used on the new domain from talking to the API on the old one. As the user base grows, you also want to expand to include mobile and desktop apps. Though ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Advanced API Security: OAuth 2.0 and Beyond

Advanced API Security: OAuth 2.0 and Beyond

Prabath Siriwardena
Logging in Action

Logging in Action

Phil Wilkins

Publisher Resources

ISBN: 9781617296024Supplemental ContentPublisher SupportOtherPublisher WebsiteSupplemental ContentPurchase Link