Book description
ASP.NET Web API is a key part of ASP.NET MVC 4 and the platform of choice for building RESTful services that can be accessed by a wide range of devices. Everything from JavaScript libraries to RIA plugins, RFID readers to smart phones can consume your services using platform-agnostic HTTP.
With such wide accessibility, securingyour code effectively needs to be a top priority. You will quickly find that the WCF security protocols you're familiar with from .NET (WS-* and similar)are less suitable than they once were in this new environment; proving themselves cumbersome and limited in terms of the standards they can work with.
Fortunately, ASP.NET Web API provides asimple robust security solution of its own that fits neatly within the ASP.NET MVC programming model and secures your code without the need for SOAP meaningthat there is no limit to the range of devices that it can work with – if it can understand HTTP then it can be secured by Web API. These SOAP-less security techniques are the focus of this book.
What you'll learn
Identity management and cryptography
HTTP basic and digest authentication and Windows authentication
HTTP advanced concepts such as web caching, ETag, and CORS
Ownership factors of API keys, client X.509 certificates, and SAML tokens
Simple Web Token (SWT) and signed and encrypted JSON Web Token (JWT)
OAuth 2.0 from the ground up using JWT as the bearer token
OAuth 2.0 authorization codes and implicit grants using DotNetOpenAuth
Two-factor authentication using Google Authenticator
OWASP Top Ten risks for 2013
Who this book is for
No prior experience of .NET-security is needed to read this book. All security related concepts will be introduced from first-principles and developed to the point where you can use them confidently in a professional environment. A goodworking knowledge and experience of C# and the .NET framework are the onlypre-requisites to benefit from this book.
Table of contents
- Title Page
- Dedication
- Contents at a Glance
- Contents
- Foreword
- About the Author
- About the Technical Reviewer
- Acknowledgments
- Introduction
- CHAPTER 1: Welcome to ASP.NET Web API
- CHAPTER 2: Building RESTful Services
- CHAPTER 3: Extensibility Points
- CHAPTER 4: HTTP Anatomy and Security
- CHAPTER 5: Identity Management
- CHAPTER 6: Encryption and Signing
- CHAPTER 7: Custom STS through WIF
- CHAPTER 8: Knowledge Factors
- CHAPTER 9: Ownership Factors
- CHAPTER 10: Web Tokens
- CHAPTER 11: OAuth 2.0 Using Live Connect API
- CHAPTER 12: OAuth 2.0 from the Ground Up
- CHAPTER 13: OAuth 2.0 Using DotNetOpenAuth
- CHAPTER 14: Two-Factor Authentication
- CHAPTER 15: Security Vulnerabilities
- APPENDIX: ASP.NET Web API Security Distilled
- Index
Product information
- Title: Pro ASP.NET Web API Security: Securing ASP.NET Web API
- Author(s):
- Release date: March 2013
- Publisher(s): Apress
- ISBN: 9781430257820
You might also like
book
ASP.NET Web API Security Essentials
Take the security of your ASP.NET Web API to the next level using some of the …
book
Pro ASP.NET Web API: HTTP Web Services in ASP.NET
Pro ASP.NET Web API shows you how to build flexible, extensible web services that run seamlessly …
book
Mastering ASP.NET Web API
Leverage ASP.Net Web API to build professional web services and create powerful applications. About This Book …
book
ASP.NET Core Security
Secure your ASP.NET applications before you get hacked! This practical guide includes secure coding techniques with …