𝔖 Scriptorium
✦   LIBER   ✦

πŸ“

Advanced API Security: OAuth 2.0 And Beyond

✍ Scribed by Prabath Siriwardena


Publisher
Apress
Year
2020
Tongue
English
Leaves
455
Category
Library

⬇  Acquire This Volume

No coin nor oath required. For personal study only.

✦ Synopsis


Prepare for the next wave of challenges in enterprise security. Learn to better protect, monitor, and manage your public and private APIs. Enterprise APIs have become the common way of exposing business functions to the outside world. Exposing functionality is convenient, but of course comes with a risk of exploitation. This book teaches you about TLS Token Binding, User Managed Access (UMA) 2.0, Cross Origin Resource Sharing (CORS), Incremental Authorization, Proof Key for Code Exchange (PKCE), and Token Exchange. Benefit from lessons learned from analyzing multiple attacks that have taken place by exploiting security vulnerabilities in various OAuth 2.0 implementations. Explore root causes, and improve your security practices to mitigate against similar future exploits. Security must be an integral part of any development project. This book shares best practices in designing APIs for rock-solid security. API security has evolved since the first edition of this book, and the growth of standards has been exponential. OAuth 2.0 is the most widely adopted framework that is used as the foundation for standards, and this book shows you how to apply OAuth 2.0 to your own situation in order to secure and protect your enterprise APIs from exploitation and attack. What You Will Learn:
β€’ Securely design, develop, and deploy enterprise APIs
β€’ Pick security standards and protocols to match business needs
β€’ Mitigate security exploits by understanding the OAuth 2.0 threat landscape
β€’ Federate identities to expand business APIs beyond the corporate firewall
β€’ Protect microservices at the edge by securing their APIs
β€’ Develop native mobile applications to access APIs securely
β€’ Integrate applications with SaaS APIs protected with OAuth 2.0
Who This Book Is For: Enterprise security architects who are interested in best practices around designing APIs. The book is also for developers who are building enterprise APIs and integrating with internal and external applications.

✦ Table of Contents


Front Matter ....Pages i-xix
APIs Rule! (Prabath Siriwardena)....Pages 1-32
Designing Security for APIs (Prabath Siriwardena)....Pages 33-67
Securing APIs with Transport Layer Security (TLS) (Prabath Siriwardena)....Pages 69-79
OAuth 2.0 Fundamentals (Prabath Siriwardena)....Pages 81-101
Edge Security with an API Gateway (Prabath Siriwardena)....Pages 103-127
OpenID Connect (OIDC) (Prabath Siriwardena)....Pages 129-155
Message-Level Security with JSON Web Signature (Prabath Siriwardena)....Pages 157-184
Message-Level Security with JSON Web Encryption (Prabath Siriwardena)....Pages 185-210
OAuth 2.0 Profiles (Prabath Siriwardena)....Pages 211-226
Accessing APIs via Native Mobile Apps (Prabath Siriwardena)....Pages 227-241
OAuth 2.0 Token Binding (Prabath Siriwardena)....Pages 243-255
Federating Access to APIs (Prabath Siriwardena)....Pages 257-276
User-Managed Access (Prabath Siriwardena)....Pages 277-286
OAuth 2.0 Security (Prabath Siriwardena)....Pages 287-304
Patterns and Practices (Prabath Siriwardena)....Pages 305-319
The Evolution of Identity Delegation (Prabath Siriwardena)....Pages 321-330
OAuth 1.0 (Prabath Siriwardena)....Pages 331-354
How Transport Layer Security Works? (Prabath Siriwardena)....Pages 355-376
UMA Evolution (Prabath Siriwardena)....Pages 377-396
Base64 URL Encoding (Prabath Siriwardena)....Pages 397-399
Basic/Digest Authentication (Prabath Siriwardena)....Pages 401-423
OAuth 2.0 MAC Token Profile (Prabath Siriwardena)....Pages 425-437
Back Matter ....Pages 439-449

✦ Subjects


Security


πŸ“œ SIMILAR VOLUMES


Advanced API Security: Securing APIs wit
✍ Prabath Siriwardena (auth.) πŸ“‚ Library πŸ“… 2014 πŸ› Apress 🌐 English

<p><p><em>Advanced</em><em> API Security</em> is a complete reference to the next wave of challenges in enterprise security--securing public and private APIs. <p>API adoption in both consumer and enterprises has gone beyond predictions. It has become the &lsquo;coolest&rsquo; way of exposing busines

Advanced API Security Securing APIs wit
✍ Prabath Siriwardena πŸ“‚ Library πŸ“… 2014 πŸ› Apress 🌐 English

Advanced API Security is a complete reference to the next wave of challenges in enterprise security--securing public and private APIs.<br>API adoption in both consumer and enterprises has gone beyond predictions. It has become the β€˜coolest’ way of exposing business functionalities to the outside wor

Advanced API Security: Securing APIs wit
✍ Prabath Siriwardena πŸ“‚ Library πŸ“… 2014 πŸ› Apress 🌐 English

Advanced API Security is a complete reference to the next wave of challenges in enterprise security - securing public and private APIs. API adoption in both consumer and enterprises has gone beyond predictions. It has become the 'coolest' way of exposing business functionalities to the outside worl

Getting Started with OAuth 2.0: Programm
✍ Ryan Boyd πŸ“‚ Library πŸ“… 2012 πŸ› O'Reilly Media 🌐 English

Whether you develop web applications or mobile apps, the OAuth 2.0 protocol will save a lot of headaches. This concise introduction shows you how OAuth provides a single authorization technology across numerous APIs on the Web, so you can securely access users data - such as user profiles, photos, v

OAuth 2.0 Cookbook: Protect your web app
✍ Adolfo Eloy Nascimento πŸ“‚ Library πŸ“… 2017 πŸ› Packt Publishing 🌐 English

<h4><span>Key Features</span></h4><ul><li><span><span>Interact with public OAuth 2.0 protected APIs such as Facebook, LinkedIn and Google.</span></span></li><li><span><span>Use Spring Security and Spring Security OAuth2 to implement your own OAuth 2.0 provider</span></span></li><li><span><span>Learn

Beyond Any Experience
✍ Anne E. Terpstra πŸ“‚ Fiction πŸ“… 2022 πŸ› NineStar Press, LLC 🌐 English

<p>Olivia Northman's world shattered the day she lost her wife to a drunk driver. Three years later, she still struggles with grief and the demands of being a single parent to their autistic son, Ben. After her first attempt at a new relationship crumbles, Olivia retreats to the simple, the predicta