Spring 框架是否支持 REST 安全性?
我即将基于 Spring 框架为我的 RESTful 服务实现安全性。实际上,我以前从未保护过 RESTful WS,但我对自己有一个很好的介绍 此处。基本上,Amazon S3 甚至 OAuth 都是很好的例子。
我的问题:
- Spring 框架是否提供了这些开箱即用的策略?
- 如果是:是 Spring security 实现了这些策略吗?
- 如果不是:您建议如何使用 Spring 实施这些策略(OAuth ...)?
预先感谢您的任何建议。
呃
I am about to implement security for my RESTful services based on the Spring framework. Actually, I have never secured RESTful WS before, but I've got myself a good introduction here. Basically, Amazon S3 or even OAuth are suggested as good examples.
My questions:
- Does the Spring framework provide these strategies out-of-the-box?
- If yes: Is it Spring security that implements these strategies?
- If no: How would you suggest to implement these strategies (OAuth ...) with Spring?
Thanks in advance for any suggestion.
Er
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。
data:image/s3,"s3://crabby-images/d5906/d59060df4059a6cc364216c4d63ceec29ef7fe66" alt="扫码二维码加入Web技术交流群"
绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(1)
这绝对是您正在寻找的 Spring Security。它提供了一种保护 RESTful spring-mvc 控制器调用安全的绝佳方法。
oAuth 涉及联合授权,当您构建一个应用程序,要求其用户向您的应用程序授予访问其存储在云中的部分私有数据(例如,他们的 Gmail 联系人或他们的个人数据)的应用程序时,您需要联合授权。谷歌日历。
It is definitely Spring Security that you're looking for. It provides an excellent way of securing the invocations of your RESTful spring-mvc controllers.
oAuth is in the business of federated authorization, which is what you need when you're building an application that requires its users to give your application permission to access a portion of their private data that lives in the cloud, e.g their gmail contacts or their Google Calendar.