[OTDev] AA using the Header 'Authorization'

chung chvng at mail.ntua.gr
Fri Nov 26 22:35:33 CET 2010


Dear All,
  In the last meeting we concluded that it is better to provide the
authentication token to a service in the HTTP header instead of as a URL
parameter. This is also recommended by the RFC 2616 specifications. I
updated the API at http://opentox.org/dev/apis/api-1.2/AA and we
currently work on providing AA functionality using the header. We have
currently turned off AA on opentox.ntua.gr and will turn it on again on
Monday following the latest specifications. Just note that on port 3000
the services will run without AA and a protected instance of the
services will be available on port 3001. 

Best Regards,
Pantelis



More information about the Development mailing list